Courseiva

CCNA Dev AWS Services Questions

75 of 388 questions · Page 3/6 · Dev AWS Services topic · Answers revealed

151
MCQmedium

A company is using Amazon CloudFront to distribute static content from an S3 bucket. The content is updated frequently, but users see stale content. The developer wants to ensure that new content is served as soon as possible after an update. Which action should be taken?

A.Enable 'Origin Shield' to reduce the number of requests to S3.
B.Set the 'Minimum TTL' to 0 and 'Default TTL' to 0.
C.Set the 'Object Caching' to 0 in the CloudFront distribution.
D.Create a CloudFront invalidation for the updated files.
AnswerD

Creating a CloudFront invalidation request specifically targets and removes specified objects from all CloudFront edge caches globally. Upon successful invalidation, the next request for those objects at any edge location will result in CloudFront fetching the latest version directly from the origin. This is the most direct and effective method to ensure users immediately receive updated content after changes have been deployed to the origin, overriding any existing TTL settings.

Why this answer

CloudFront caches content at edge locations based on TTL settings. When content is updated in the S3 origin, existing cached copies remain stale until they expire or are explicitly invalidated. Creating a CloudFront invalidation for the updated files immediately removes the cached objects from all edge locations, forcing CloudFront to fetch the latest version from S3 on the next request.

This ensures new content is served as soon as possible after an update.

Exam trap

The trap here is that candidates confuse TTL configuration (which controls how long new objects are cached) with invalidation (which removes already-cached objects), leading them to pick options that only affect future caching behavior without addressing the stale content already served.

How to eliminate wrong answers

Option A is wrong because enabling Origin Shield reduces the number of requests to the S3 origin by consolidating them at a regional cache layer, but it does not force CloudFront to serve fresh content; it can actually increase staleness by adding another caching layer. Option B is wrong because setting Minimum TTL and Default TTL to 0 tells CloudFront to respect the Cache-Control max-age=0 header from the origin, but if the S3 object does not have that header (or has a higher max-age), CloudFront will still cache the content for the origin's specified duration; TTL settings alone do not purge already-cached content. Option C is wrong because 'Object Caching' is not a configurable numeric field in CloudFront; the correct setting is 'Minimum TTL', 'Maximum TTL', and 'Default TTL' under the 'Cache Based on Selected Request Headers' behavior, and setting these to 0 does not invalidate existing cached objects.

152
MCQhard

An IAM policy attached to an IAM user. What is the effect of this policy on the user's ability to delete objects in the bucket my-bucket?

A.The user can delete objects from any IP address.
B.The user is denied the ability to delete objects regardless of source IP.
C.The user can delete objects only if the source IP is not 192.0.2.0/24.
D.The user can delete objects only if the source IP is 192.0.2.0/24.
AnswerB

No Allow statement exists for DeleteObject, so implicit deny applies.

Why this answer

The question cannot be answered as written because the IAM policy text is missing. To determine the effect on s3:DeleteObject, the policy's Effect, Action, and Condition (including any IpAddress or NotIpAddress operators) must be provided. Without the policy, no option can be verified as correct.

Exam trap

The trap described assumes a specific policy containing a Deny effect with a NotIpAddress condition, but no such policy is shown in the stem. Candidates cannot apply this reasoning without the actual policy text.

How to eliminate wrong answers

Option A is wrong because the policy includes a `Deny` effect with a `NotIpAddress` condition that denies `s3:DeleteObject` from any IP not in 192.0.2.0/24, and an explicit deny for the 192.0.2.0/24 range, so the user cannot delete from any IP. Option C is wrong because the policy does not allow deletion from IPs outside 192.0.2.0/24; it explicitly denies deletion from those IPs via the `NotIpAddress` condition. Option D is wrong because the policy explicitly denies deletion from the 192.0.2.0/24 range, so the user cannot delete from that IP range either.

153
Multi-Selectmedium

A DynamoDB query must support lookup by email address as well as by user ID. Which two changes may be required?

Select 2 answers
A.Create a secondary index with email as a key
B.Scan the full table for every login
C.Choose projection attributes needed by the query
D.Disable partition keys
AnswersA, C

This is the primary mechanism in DynamoDB to efficiently query data using an attribute other than the table's primary key. By defining a Global Secondary Index (GSI) with email as its partition key, DynamoDB builds a separate, sparse table that allows direct, high-performance lookups based on email addresses. This approach avoids costly full table scans and ensures predictable, low-latency access for user authentication or profile retrieval.

Why this answer

A Global Secondary Index (GSI) or Local Secondary Index (LSI) on the email attribute allows DynamoDB to efficiently query by email address without scanning the entire table. Since the primary key is user ID, querying by email requires an index that uses email as the partition key or sort key. Option C is correct because specifying projection attributes limits the data returned from the index or table, reducing read capacity consumption and improving performance.

Exam trap

The trap here is that candidates may think a Scan is acceptable for low-volume logins, but the exam emphasizes that any production authentication system must use an index to avoid full table scans and meet latency requirements.

154
MCQeasy

A developer needs to store session state for a stateless web application running on EC2 instances behind an Application Load Balancer. Which AWS service should the developer use to ensure session data is not lost if an instance fails?

A.Amazon S3
B.Amazon DynamoDB
C.Amazon ElastiCache
D.Amazon RDS
AnswerB

DynamoDB is a NoSQL key-value store, not a session state cache; it lacks the low-latency, in-memory read performance and automatic expiry mechanisms that ElastiCache provides for session management. It is tempting because it offers durable, scalable storage for any application data, and would be correct for persisting session history or user profiles across restarts, but the stem requires a solution that prevents data loss during instance failure without introducing the latency of disk-based persistence.

Why this answer

Amazon DynamoDB is a fully managed NoSQL database that provides fast and predictable performance with seamless scalability. It is highly recommended for storing session state in stateless applications because it is serverless, highly durable, and requires no cluster management, unlike ElastiCache. AWS SDKs even offer native session state providers for DynamoDB.

Exam trap

Do not assume ElastiCache is always the only choice for session state. While ElastiCache (Redis) is an excellent in-memory option, DynamoDB is the standard serverless, durable key-value store recommended for session state in many DVA-C02 scenarios because it requires no cluster provisioning or management.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service designed for static files and large data blobs, not for low-latency session state access; its read/write latency and lack of native key-value expiration make it unsuitable for real-time session management. Option B is wrong because Amazon DynamoDB, while capable of storing session data, introduces higher latency and cost compared to an in-memory cache like ElastiCache, and its primary use case is for persistent, scalable NoSQL workloads rather than ephemeral session state. Option D is wrong because Amazon RDS is a relational database service that incurs significant overhead for frequent session reads/writes, and its connection pooling and disk-based I/O are not optimized for the sub-millisecond access patterns required for session state in a stateless web application.

155
MCQmedium

A developer is deploying a serverless application using AWS SAM. The application includes an API Gateway endpoint that invokes a Lambda function. The developer wants to pass a stage name as a parameter to the Lambda function. How should the developer define the Lambda function's environment variable in the SAM template?

A.Use the parameter reference 'Ref: StageName' in the environment variable mapping.
B.Define the environment variable as 'Stage: dev' in the Lambda function configuration.
C.Use 'Fn::GetAtt: [AWS::StackName, Outputs.StageName]' to get the stage name.
D.Use 'Fn::ImportValue: StageName' to import from another stack.
AnswerA

This is the correct approach for dynamically injecting a value provided at deployment time into a Lambda function's environment variables. `Ref` is a CloudFormation intrinsic function that retrieves the value of a top-level parameter declared in the `Parameters` section of the template. By defining `StageName` as a parameter and referencing it with `Ref: StageName` in the Lambda's environment variable configuration, the developer ensures the stage name (e.g., 'dev', 'prod') is passed during stack creation or update, making the application adaptable across different environments without code changes.

Why this answer

The developer should use the parameter reference 'Ref: StageName' in the environment variable mapping. In AWS SAM, you can reference parameters defined in the template using the Ref intrinsic function. This allows the stage name to be passed as an environment variable to the Lambda function.

Exam trap

DVA-C02 often tests the correct use of intrinsic functions, and candidates may confuse Ref with Fn::GetAtt or Fn::ImportValue, or attempt to reference outputs incorrectly.

How to eliminate wrong answers

Option B is wrong because hardcoding 'Stage: dev' does not allow dynamic parameterization; it would always be 'dev'. Option C is wrong because 'Fn::GetAtt' is used to get attributes of resources, not outputs from the stack; there is no 'Outputs.StageName' attribute on AWS::StackName. Option D is wrong because 'Fn::ImportValue' is used to import values from other stacks, not to reference a parameter within the same template.

156
MCQmedium

A company is developing a serverless application using AWS Lambda and API Gateway. The application needs to process user uploads to Amazon S3. The Lambda function must be invoked asynchronously after an object is uploaded to an S3 bucket. Which configuration should the developer use to invoke the Lambda function?

A.Configure the S3 bucket to send events to Lambda by adding a Lambda trigger in the S3 bucket properties.
B.Configure the S3 bucket to send events to an Amazon SQS queue and have Lambda poll the queue.
C.Configure the S3 bucket to send events to Amazon CloudWatch Events and have CloudWatch invoke Lambda.
D.Configure the S3 bucket to send events to an Amazon API Gateway endpoint that triggers the Lambda function.
AnswerA

This is the most direct and efficient method. Amazon S3 natively supports event notifications, allowing you to configure a bucket to send events, such as s3:ObjectCreated:*, directly to an AWS Lambda function. When an object is uploaded, S3 asynchronously invokes the specified Lambda function, passing the event details as payload, which simplifies the architecture and minimizes latency. This setup requires granting S3 permissions to invoke the Lambda function.

Why this answer

S3 can directly invoke Lambda asynchronously via a bucket notification configuration. When an object is uploaded, S3 publishes an event to the Lambda service, which then executes the function without requiring any intermediary services. This is the simplest and most direct way to trigger a Lambda function from an S3 event.

Exam trap

The trap here is that candidates may overcomplicate the solution by introducing unnecessary intermediary services (like SQS or API Gateway) when the direct S3-to-Lambda trigger is the simplest and most appropriate asynchronous invocation method.

How to eliminate wrong answers

Option B is wrong because while S3 can send events to SQS and Lambda can poll the queue, this introduces unnecessary complexity and latency; the requirement is for asynchronous invocation, which S3-to-Lambda direct trigger already provides without an intermediary. Option C is wrong because S3 cannot send events directly to CloudWatch Events; S3 events can be sent to EventBridge (formerly CloudWatch Events) only via S3 Event Notifications configured for EventBridge, and even then, EventBridge would invoke Lambda, but this is not the standard or simplest configuration. Option D is wrong because routing S3 events through API Gateway adds an unnecessary HTTP layer and introduces potential latency and cost; API Gateway is designed for RESTful API endpoints, not for direct S3 event processing.

157
MCQhard

A developer is building a real-time chat application using Amazon API Gateway WebSocket APIs and AWS Lambda. The application needs to send messages to connected clients. The developer notices that the 'connectionId' changes every time a client reconnects. How should the developer store the mapping between user identity and connectionId?

A.Use Amazon ElastiCache to store the mapping in memory.
B.Use Amazon DynamoDB to store the mapping, with user identity as the partition key and connectionId as an attribute.
C.Use Amazon RDS to store the mapping in a relational database.
D.Use Amazon S3 to store the mapping as a JSON file.
AnswerB

Amazon DynamoDB is an excellent choice for storing real-time chat application mappings due to its consistent single-digit millisecond latency at any scale. By using the user identity as the partition key, the application can efficiently retrieve the associated connectionId for message routing with high throughput. Its fully managed, highly available, and durable nature ensures the mapping data is always accessible and resilient to failures, making it ideal for critical, frequently accessed application state.

Why this answer

Amazon DynamoDB is the recommended, fully managed, serverless key-value store for persisting WebSocket connection IDs in AWS. It offers single-digit millisecond latency, scales automatically, and integrates seamlessly with AWS Lambda without requiring VPC configuration (unlike Amazon ElastiCache, which typically requires a VPC, adding setup complexity and potential latency for Lambda functions).

Exam trap

Candidates often think of Amazon ElastiCache (Redis/Memcached) first for low-latency key-value storage. However, for serverless WebSocket applications, DynamoDB is the preferred choice because it is fully serverless, does not require VPC placement for the Lambda function (which ElastiCache typically does, increasing complexity and cold start times), and easily handles the rapid read/write patterns of connection mappings at a lower cost.

How to eliminate wrong answers

Option A is wrong because Amazon ElastiCache is an in-memory cache that does not provide data durability; if the cache is restarted or scaled, the mapping is lost, and it requires additional infrastructure management. Option C is wrong because Amazon RDS is a relational database that introduces unnecessary schema complexity, higher latency for simple key-value lookups, and requires connection pooling, which is overkill for storing a simple mapping. Option D is wrong because Amazon S3 is an object store designed for large, infrequently accessed data; storing and retrieving individual mappings as JSON files would introduce high latency and is not suitable for real-time, per-request lookups.

158
MCQeasy

A developer is creating an AWS Lambda function to process events from an Amazon SQS queue. The function must process each message exactly once and in order. Which SQS queue type should the developer use?

A.Standard queue.
B.FIFO queue.
C.Dead-letter queue.
D.Delay queue.
AnswerB

Amazon SQS FIFO (First-In-First-Out) queues are designed to guarantee message ordering and exactly-once processing. They ensure that messages are processed in the exact order they are sent and prevent duplicates from being delivered to the consumer, thanks to message deduplication IDs and message group IDs. This makes FIFO queues ideal for applications where the sequence of operations and the prevention of duplicate processing are critical for data integrity.

Why this answer

FIFO queue. FIFO (First-In-First-Out) queues guarantee exactly-once processing and preserve the order of messages, which is required by the use case. Standard queues offer at-least-once delivery and do not guarantee order, making them unsuitable for this requirement.

Exam trap

The trap here is that candidates often confuse the 'exactly-once' and 'in-order' requirements with Standard queues, assuming they can achieve this with idempotent processing, but Standard queues explicitly do not guarantee order and can deliver duplicates.

How to eliminate wrong answers

Option A is wrong because Standard queues provide at-least-once delivery, meaning a message can be delivered more than once, and they do not guarantee message order. Option C is wrong because a Dead-letter queue is not a primary queue type; it is a secondary queue used to store messages that failed processing, not to process events in order with exactly-once semantics. Option D is wrong because a Delay queue is a feature of both Standard and FIFO queues that introduces a message delivery delay, but it does not provide exactly-once processing or ordering guarantees.

159
MCQeasy

A developer is building a serverless application using AWS Lambda to process files uploaded to an S3 bucket. The Lambda function needs to read the uploaded file, transform it, and write the result to a DynamoDB table. Which IAM policy statement should be attached to the Lambda execution role?

A.{"Effect":"Allow","Action":["s3:GetObject","dynamodb:PutItem"],"Resource":"*"}
B.{"Effect":"Allow","Action":["s3:PutObject","dynamodb:PutItem"],"Resource":"*"}
C.{"Effect":"Allow","Action":["s3:GetObject","dynamodb:UpdateItem"],"Resource":"*"}
D.{"Effect":"Allow","Action":["s3:GetObject","dynamodb:GetItem"],"Resource":"*"}
AnswerA

s3:GetObject correctly grants permission to download the uploaded file's bytes from the S3 bucket for processing, and dynamodb:PutItem correctly grants permission to insert or overwrite the transformed result as a new item, which matches the function's actual read-from-S3, write-to-DynamoDB data flow exactly.

Why this answer

The Lambda function needs to read the uploaded file from S3 (requiring s3:GetObject) and write the transformed result to DynamoDB (requiring dynamodb:PutItem). Option A correctly grants both actions with a wildcard resource, which is acceptable for a learning scenario but should be scoped in production. This matches the exact permissions needed for the described workflow.

Exam trap

The trap here is confusing the direction of data flow: candidates mistakenly choose write permissions for S3 (s3:PutObject) or read permissions for DynamoDB (dynamodb:GetItem), failing to map the correct action to each service based on whether data is being read from or written to that service.

How to eliminate wrong answers

Option B is wrong because it grants s3:PutObject (write to S3) instead of s3:GetObject (read from S3); the Lambda only reads the uploaded file, not writes back to S3. Option C is wrong because it grants dynamodb:UpdateItem (modify an existing item) instead of dynamodb:PutItem (create a new item); the requirement is to write the result, which implies inserting a new record, not updating an existing one. Option D is wrong because it grants dynamodb:GetItem (read from DynamoDB) instead of dynamodb:PutItem; the Lambda writes to DynamoDB, not reads from it.

160
MCQhard

A development team is building a real-time chat application using Amazon API Gateway WebSocket APIs and AWS Lambda. The application needs to maintain a connection to each user and broadcast messages to all connected clients. Which approach should the developer use to scale the application efficiently?

A.Store connection IDs in Amazon DynamoDB and use the API Gateway Management API to send messages to all connections.
B.Use Amazon ElastiCache to cache connection IDs and have Lambda send messages using the Redis pub/sub feature.
C.Use Amazon SNS to publish messages to all connected clients via the WebSocket API.
D.Use Amazon SQS to queue messages and have Lambda poll the queue to send messages to all connections.
AnswerA

This is the correct and standard architectural pattern for serverless WebSocket applications on AWS. When a client connects, API Gateway invokes an onConnect Lambda function which stores the unique connectionId in a DynamoDB table. To send a message to all connected clients, a backend service (e.g., another Lambda function) retrieves all active connectionId's from DynamoDB and then iteratively calls the API Gateway Management API's postToConnection action for each ID, pushing the message directly to the client.

Why this answer

DynamoDB provides a scalable, serverless key-value store to persist WebSocket connection IDs, and the API Gateway Management API allows Lambda to send messages directly to any connected client via its connection ID. This combination efficiently handles the broadcast requirement without managing infrastructure, as Lambda can iterate over stored connection IDs and call the Management API for each message.

Exam trap

The trap here is that candidates may confuse the pub/sub or queuing services (SNS, SQS, ElastiCache) as direct communication channels to WebSocket clients, overlooking that API Gateway requires the Management API for server-to-client messaging and that DynamoDB is the simplest way to store and retrieve connection IDs at scale.

How to eliminate wrong answers

Option B is wrong because ElastiCache with Redis pub/sub is designed for decoupled messaging between services, not for directly sending messages to WebSocket clients via API Gateway; it would require additional custom logic to map Redis channels to connection IDs and invoke the Management API. Option C is wrong because Amazon SNS is a pub/sub notification service that pushes messages to endpoints like HTTP/S, email, or Lambda, but it cannot directly send messages to WebSocket connections managed by API Gateway. Option D is wrong because Amazon SQS is a message queue that decouples producers and consumers, but it does not provide a mechanism to send messages to WebSocket clients; Lambda would still need to poll the queue and use the Management API, adding latency and complexity without benefit for real-time broadcasting.

161
MCQmedium

A company runs a batch processing job on Amazon ECS using Fargate. The job processes files from an S3 bucket and writes results to another S3 bucket. The job runs once per day and takes about 30 minutes. The company wants to reduce costs by stopping the ECS service when not in use. Which solution should the developer implement?

A.Use an AWS Lambda function to run the job and configure a scheduled event in Amazon EventBridge.
B.Use AWS Batch with a Fargate launch type and schedule the job with Amazon EventBridge.
C.Use Amazon ECS Service Auto Scaling to scale the service down to zero tasks when not in use.
D.Use an Amazon EC2 Auto Scaling group to launch an instance, run the job, and then terminate.
AnswerB

AWS Batch is specifically designed for running batch computing workloads, efficiently managing job queues, compute environments, and job execution. Utilizing the Fargate launch type eliminates the need to provision and manage EC2 instances, providing a serverless experience where resources are automatically provisioned and scaled down to zero when jobs are not running. Scheduling the job with Amazon EventBridge ensures reliable, time-based invocation of the batch process, making this a robust, serverless, and cost-effective solution for a 30-minute batch job.

Why this answer

AWS Batch with a Fargate launch type is the ideal solution because it is purpose-built for batch processing jobs that run to completion. By scheduling the job with Amazon EventBridge, you can trigger the job once per day, and AWS Batch automatically provisions the Fargate compute environment only when the job runs, then scales down to zero after completion—eliminating costs during idle periods. This approach directly addresses the requirement to reduce costs by stopping the ECS service when not in use, without manual intervention.

Exam trap

The trap here is that candidates often confuse ECS Service Auto Scaling with AWS Batch's job-based scaling; while ECS can scale to zero tasks, it does not automatically manage job completion and termination, leading to residual costs and complexity, whereas AWS Batch is designed for exactly this use case.

How to eliminate wrong answers

Option A is wrong because while a Lambda function could process files from S3, it has a maximum execution timeout of 15 minutes, which is insufficient for a job that takes about 30 minutes, and it cannot directly write results to another S3 bucket in the same manner as a batch job. Option C is wrong because Amazon ECS Service Auto Scaling can scale the desired count to zero, but it does not automatically stop the service after the job completes; the service remains defined and incurs costs for the Fargate infrastructure even at zero tasks (e.g., load balancer or network costs), and it lacks native job scheduling and lifecycle management for batch workloads. Option D is wrong because using an EC2 Auto Scaling group to launch an instance for a 30-minute job is inefficient; it requires managing the instance lifecycle, patching, and termination, and incurs costs for the running instance and associated resources, whereas Fargate with AWS Batch provides a serverless, cost-effective alternative that scales to zero automatically.

162
MCQeasy

A developer is deploying a containerized application on Amazon ECS using Fargate. The application needs to store sensitive configuration data, including database passwords, that must be rotated regularly. Which service should the developer use to manage these secrets securely?

A.Amazon S3 with server-side encryption
B.AWS Secrets Manager
C.Amazon DynamoDB with server-side encryption
D.AWS Systems Manager Parameter Store
AnswerB

AWS Secrets Manager stores the database passwords and supports automatic rotation through Lambda rotation functions, meeting the regular-rotation requirement. ECS Fargate tasks retrieve secrets at launch via the secrets parameter, so credentials never persist in task definitions or images.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, retrieving, and automatically rotating sensitive configuration data such as database passwords. It integrates natively with Amazon ECS (via the `secrets` container definition parameter) and supports automatic rotation using AWS Lambda, which meets the requirement for regular rotation without custom code.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets but lacks native rotation) with AWS Secrets Manager, overlooking the explicit requirement for 'regular rotation' in the question.

How to eliminate wrong answers

Option A is wrong because Amazon S3 with server-side encryption provides static encryption at rest but lacks native secret rotation capabilities and does not integrate directly with ECS task definitions for injecting secrets as environment variables. Option C is wrong because Amazon DynamoDB with server-side encryption is a NoSQL database service designed for high-performance data storage, not for managing secrets with built-in rotation or fine-grained access control for secret lifecycle management. Option D is wrong because AWS Systems Manager Parameter Store can store secrets (using SecureString parameters) but does not support automatic rotation of secrets; it requires custom automation to rotate values, whereas the question explicitly requires regular rotation.

163
MCQhard

A developer runs the AWS CLI command shown. The Lambda function returns a 200 status code but the output file is null and the response includes FunctionError: Unhandled. What does this indicate?

A.The Lambda function timed out.
B.The Lambda function threw an unhandled exception.
C.The payload was too large for synchronous invocation.
D.The Lambda function was not found.
AnswerB

When a Lambda function throws an unhandled exception, the Lambda service captures this error and returns a 200 OK HTTP status code to the invoker, but includes a special X-Amz-Function-Error header with the value Unhandled. This header explicitly indicates that the function's execution failed due to an exception that was not caught and handled within the function's code, even though the invocation request itself was successfully received and processed by the Lambda service.

Why this answer

The presence of `FunctionError: Unhandled` in the response of an `aws lambda invoke` command indicates that the Lambda function encountered an error (such as an unhandled exception or runtime crash) that was not caught by the function's code. Even though the function failed, the Invoke API itself successfully completed the transaction of invoking the function, which is why it returns an HTTP status code of 200.

Exam trap

The trap here is that candidates often assume a 200 status code means success, but AWS Lambda's synchronous invocation returns HTTP 200 even for function errors, with the `FunctionError` field distinguishing success from failure.

How to eliminate wrong answers

Option A is wrong because a timeout would produce a `FunctionError: Unhandled` only if the timeout exception itself is unhandled, but the specific error message for a timeout is `Task timed out after X seconds` and the response would include a `StatusCode` of 200 with `FunctionError: Unhandled` only if the runtime throws an unhandled exception after the timeout; however, the question states the output file is null and the response includes `FunctionError: Unhandled`, which directly matches an unhandled exception, not a timeout. Option C is wrong because the payload size limit for synchronous invocation is 6 MB, and exceeding it would result in a `413 Request Entity Too Large` error or a `PayloadTooLarge` exception, not a 200 status code with `FunctionError: Unhandled`. Option D is wrong because if the Lambda function were not found, the AWS CLI command would return a `ResourceNotFoundException` error with a 404 status code, not a 200 status code.

164
MCQmedium

A company has a DynamoDB table that stores order data. The table has a partition key of OrderID and a sort key of OrderDate. The company frequently queries orders by CustomerID, which is not a key attribute. The queries are slow and consume a lot of read capacity. Which design change would MOST improve query performance?

A.Increase the provisioned read capacity for the table.
B.Create a Global Secondary Index (GSI) with CustomerID as the partition key.
C.Change the table's primary key to use CustomerID as the partition key.
D.Use a FilterExpression on the CustomerID attribute in a Scan operation.
AnswerB

Creating a Global Secondary Index (GSI) with `CustomerID` as its partition key is the most effective solution for efficiently querying items based on `CustomerID`. A GSI stores a copy of a subset of the base table's attributes, indexed by its own primary key (in this case, `CustomerID`). This allows `Query` operations to directly access items matching a specific `CustomerID` without scanning the entire base table, significantly improving performance and reducing cost for targeted lookups.

Why this answer

Creating a Global Secondary Index (GSI) with CustomerID as the partition key allows DynamoDB to efficiently query orders by CustomerID using the index's key structure, avoiding full table scans. This directly addresses the slow performance and high read capacity consumption by enabling targeted lookups instead of scanning all items and filtering.

Exam trap

The trap here is that candidates often think increasing provisioned capacity (Option A) or using FilterExpression (Option D) will fix performance, but they fail to recognize that these do not change the underlying inefficient data access pattern of scanning all items.

How to eliminate wrong answers

Option A is wrong because increasing provisioned read capacity only adds more throughput capacity but does not change the underlying query pattern; the query still performs a full Scan or inefficient query, so it would still be slow and consume more capacity units. Option C is wrong because changing the table's primary key to CustomerID would break existing access patterns that rely on OrderID as the partition key, and it would not support queries by OrderID without a separate index. Option D is wrong because using a FilterExpression on a Scan operation still reads every item in the table, consuming the same amount of read capacity and providing no performance improvement; FilterExpressions only reduce the data returned, not the data read.

165
MCQeasy

A developer wants to upload a large file (5 GB) to an Amazon S3 bucket using the AWS SDK. Which approach is MOST efficient and resilient?

A.Generate a presigned URL and use a third-party tool to upload.
B.Invoke an AWS Lambda function to upload the file.
C.Use the Multipart Upload API to upload the file in parts.
D.Use the PutObject API call with the entire file.
AnswerC

The Amazon S3 Multipart Upload API is the recommended and most efficient method for uploading large objects, specifically designed for files up to 5 TB. It allows a 5 GB file to be broken into smaller, independently uploaded parts, significantly improving throughput and resilience. This approach enables parallel uploads, easy resumption of failed parts, and enhanced fault tolerance against network issues, making it ideal for this scenario.

Why this answer

The Multipart Upload API is specifically designed for large objects (over 100 MB, recommended for 5 GB). It allows uploading a file in parallel parts, which improves throughput and resilience by enabling retries of individual failed parts without restarting the entire upload. This approach also supports pausing and resuming uploads, making it the most efficient and resilient method for a 5 GB file.

Exam trap

The trap here is that candidates may assume the PutObject API (Option D) is sufficient for large files because it supports up to 5 GB, but they overlook the lack of parallel uploads and partial failure recovery, which the Multipart Upload API provides and is explicitly recommended by AWS for files over 100 MB.

How to eliminate wrong answers

Option A is wrong because generating a presigned URL delegates the upload to a third-party tool, which introduces external dependencies and does not inherently provide the parallel upload or retry capabilities of the Multipart Upload API, reducing resilience and control. Option B is wrong because invoking an AWS Lambda function to upload the file is inefficient; Lambda has a maximum execution timeout of 15 minutes and a deployment package size limit of 250 MB (unzipped), making it unsuitable for handling a 5 GB upload directly, and it adds unnecessary complexity and latency. Option D is wrong because the PutObject API call has a maximum object size limit of 5 GB in a single PUT operation, but it does not support parallel uploads or partial retries; if the upload fails, the entire file must be re-uploaded, making it less resilient and efficient for large files compared to Multipart Upload.

166
MCQeasy

A developer has an Amazon S3 bucket containing private user documents. The application must generate a time-limited URL for users to download their own documents without requiring the users to have AWS credentials. Which solution should the developer use?

A.Use CloudFront signed URLs with an origin access identity (OAI) to restrict access to the S3 bucket.
B.Create a pre-signed URL for each object using the AWS SDK with an appropriate expiration time.
C.Set a bucket policy that allows public read access for the specific users based on their IP addresses.
D.Provide the users with IAM user credentials that have read access to the bucket.
AnswerB

Creating a pre-signed URL for each object using the AWS SDK is the most secure and efficient method for granting temporary access to private S3 objects. This URL, generated with the developer's AWS credentials and a specified expiration time, allows any recipient to perform a specific action (e.g., GET) on the object directly from S3 without needing their own AWS credentials. It provides granular, time-limited access, perfectly aligning with the need for secure access to private user documents.

Why this answer

Pre-signed URLs allow temporary, time-limited access to private S3 objects without requiring the user to have AWS credentials. The developer generates the URL server-side using the AWS SDK, embedding an expiration time, and the user can download the object directly via HTTP GET. This meets the requirement of granting ephemeral access to specific documents for unauthenticated users.

Exam trap

The trap here is that candidates often confuse pre-signed URLs with CloudFront signed URLs, thinking the CDN is required for time-limited access, but pre-signed URLs work directly with S3 and are simpler for single-object, time-limited downloads without needing CloudFront.

How to eliminate wrong answers

Option A is wrong because CloudFront signed URLs with OAI are used to control access at the CDN edge, but they still require the developer to manage CloudFront distributions and signing keys; the question asks for a simpler, direct S3 solution without requiring users to have AWS credentials. Option C is wrong because setting a bucket policy for public read access based on IP addresses would expose the bucket to all users from those IPs, violating the requirement for per-user, per-document private access and not providing time-limited URLs. Option D is wrong because providing IAM user credentials to end users is a security anti-pattern; it would require distributing long-term credentials, violating the principle of least privilege and the requirement that users not have AWS credentials.

167
MCQmedium

A developer is building a serverless application using AWS Step Functions. The workflow must execute hundreds of thousands of short-lived tasks per day, each taking less than 30 seconds. The tasks need to run in parallel, and a small number of duplicate executions are acceptable. Which type of Step Functions workflow should the developer choose?

A.Standard Workflow
B.Express Workflow
C.AWS Lambda function with synchronous invocation
D.Amazon Simple Workflow Service (SWF)
AnswerB

Express Workflows are optimized for high-volume, short-duration executions (under 5 minutes) with at-least-once delivery. They can handle hundreds of thousands of executions per second at a lower cost, making them suitable for this use case.

Why this answer

Express Workflows are designed for high-volume, short-duration (under 5 minutes) event-processing workloads, executing hundreds of thousands of state transitions per second with at-least-once semantics. Since the tasks are short-lived (under 30 seconds), run in parallel, and tolerate a small number of duplicate executions, Express Workflow is the correct choice because it offers lower cost and higher throughput than Standard Workflow, which guarantees exactly-once execution and is better suited for long-running, auditable workflows.

Exam trap

The trap here is that candidates often assume Standard Workflow is always the default choice for Step Functions, overlooking the specific requirements for high throughput, short duration, and tolerance for duplicates that make Express Workflow the correct answer.

How to eliminate wrong answers

Option A is wrong because Standard Workflow is designed for long-running, durable workflows with exactly-once execution and a maximum execution duration of one year, making it over-provisioned and more expensive for high-volume, short-lived tasks where duplicate executions are acceptable. Option C is wrong because AWS Lambda synchronous invocation is not a Step Functions workflow type; it is a compute invocation pattern that lacks the orchestration, state management, and parallel execution capabilities provided by Step Functions. Option D is wrong because Amazon Simple Workflow Service (SWF) is a legacy service for long-running, human-in-the-loop workflows, not optimized for high-throughput, short-lived automated tasks, and it requires managing workers and deciders, adding operational overhead.

168
Multi-Selecthard

A company is deploying a containerized application on Amazon ECS using the Fargate launch type. The application must be highly available across multiple Availability Zones. The developer needs to configure the ECS service. Which THREE configuration options are required? (Choose THREE.)

Select 3 answers
A.Create an Auto Scaling group for the Fargate tasks.
B.Set the desired number of tasks to at least 2.
C.Associate an Application Load Balancer with the ECS service.
D.Configure the service to place tasks in at least two subnets in different Availability Zones.
E.Use a DynamoDB table to store task state.
AnswersB, C, D

Setting the desired number of tasks to at least two is a fundamental practice for achieving high availability and fault tolerance in a containerized application. If a single task becomes unhealthy, crashes, or needs to be replaced during a deployment, the remaining tasks can continue to process requests, preventing service interruption. This redundancy ensures the application remains operational even with individual task failures.

Why this answer

Option B is correct because setting the desired task count to at least 2 ensures that more than one task replica runs, which is necessary for high availability so that the service survives the failure of a single task. Option C is correct because associating an Application Load Balancer with the ECS service distributes incoming traffic across the running tasks and performs health checks, enabling traffic to be routed only to healthy tasks in multiple AZs. Option D is correct because configuring the service to place tasks in at least two subnets in different Availability Zones spreads the tasks across distinct AZs, which is the fundamental requirement for multi-AZ high availability in ECS.

Option A is not required because AWS Fargate is a serverless launch type that does not use EC2 Auto Scaling groups; scaling is handled through ECS Service Auto Scaling instead. Option E is not required because ECS manages task state internally, and DynamoDB is not part of the ECS service configuration for high availability.

Exam trap

Candidates often confuse the EC2 launch type with the Fargate launch type. Auto Scaling groups (Option A) are used to scale EC2 instances in an ECS cluster using the EC2 launch type, whereas Fargate manages the underlying infrastructure serverlessly. Additionally, while external state storage (Option E) is a best practice for stateless applications, it is not an ECS service configuration requirement for high availability.

169
MCQeasy

A developer needs to analyze real-time streaming data from thousands of devices. The data consists of JSON messages that must be processed and stored in Amazon S3. Which AWS service should the developer use to ingest and buffer the streaming data?

A.Amazon S3
B.AWS Lambda
C.Amazon Simple Queue Service (SQS)
D.Amazon Kinesis Data Streams
AnswerD

Amazon Kinesis Data Streams is a fully managed, scalable service specifically engineered for real-time ingestion, processing, and analysis of large streams of data records. It provides the necessary throughput and low latency to capture continuous data from various sources, making it ideal for real-time analytics, log processing, and live dashboards. Multiple applications can concurrently consume data from a stream, enabling diverse real-time use cases.

Why this answer

Amazon Kinesis Data Streams is designed for real-time ingestion and buffering of large-scale streaming data, such as JSON messages from thousands of devices. It can capture and store data in shards for up to 365 days, allowing downstream consumers (e.g., Lambda, Kinesis Data Analytics) to process the data before storing it in Amazon S3. This makes it the correct choice for ingesting and buffering the streaming data before persistent storage.

Exam trap

The trap here is that candidates often confuse Amazon SQS with Kinesis Data Streams, but SQS is a pull-based queue for decoupling microservices, not a streaming data platform with shard-based parallelism and long-term retention, which is required for ingesting high-throughput real-time data from thousands of devices.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service, not a streaming ingestion or buffer service; it cannot ingest real-time streaming data directly without an intermediary like Kinesis or API Gateway. Option B is wrong because AWS Lambda is a serverless compute service that can process streaming data but is not designed to ingest or buffer data; it runs on demand and has a maximum execution timeout of 15 minutes, making it unsuitable as a primary ingestion buffer. Option C is wrong because Amazon SQS is a message queue service for decoupling applications, but it is not optimized for real-time streaming from thousands of devices; it lacks shard-level parallelism, has a maximum message size of 256 KB, and does not support ordered replay or long-term buffering like Kinesis Data Streams.

170
MCQmedium

A REST API requires request validation before invoking Lambda to reduce unnecessary function executions for malformed payloads. Where should validation be configured?

A.Inside the Lambda timeout setting
B.In the IAM execution role
C.In the S3 bucket policy
D.In API Gateway request models and validators
AnswerD

API Gateway provides built-in request validation capabilities through the use of request models and validators. Developers can define JSON Schema models for the request body, headers, and query parameters. When enabled for a specific API method, API Gateway automatically validates incoming requests against these defined models *before* invoking the backend integration, such as a Lambda function, returning a 400 Bad Request error for invalid payloads.

Why this answer

API Gateway provides built-in request validation using models (JSON Schema) and validators. By configuring validation at the API Gateway layer, malformed payloads are rejected before they reach the Lambda function, reducing unnecessary invocations and associated costs. This is the correct approach because API Gateway acts as the entry point for REST APIs and can enforce payload structure without invoking the backend.

Exam trap

The trap here is that candidates may confuse Lambda's execution role or timeout settings with request validation, not realizing that API Gateway is the correct layer to filter malformed payloads before they trigger Lambda.

How to eliminate wrong answers

Option A is wrong because the Lambda timeout setting controls how long a function can run, not whether it is invoked; it cannot prevent invocation for malformed payloads. Option B is wrong because the IAM execution role defines permissions for the Lambda function to access other AWS services, not request validation. Option C is wrong because S3 bucket policies control access to S3 objects, not API request validation; they are unrelated to REST API payload checking.

171
MCQmedium

A developer is using Amazon S3 to host a static website. The website uses JavaScript to fetch data from an API Gateway endpoint. Users report that the website loads but API calls fail with HTTP 403 errors. The developer checks the S3 bucket policy and finds it allows public read access. What is the most likely cause?

A.The S3 bucket policy blocks access from the API Gateway domain.
B.The S3 bucket is not configured for static website hosting.
C.The API Gateway API key is not included in the JavaScript code.
D.The S3 bucket does not have CORS configuration to allow cross-origin requests from the API Gateway domain.
AnswerC

When an API Gateway method is configured to require an API key, every incoming request must include a valid `x-api-key` header. If the JavaScript code making the API call omits this essential header, or provides an incorrect or expired key, API Gateway will reject the request with a `403 Forbidden` status code. This indicates that the request reached API Gateway but was denied due to a lack of proper authentication credentials.

Why this answer

The website loads from S3, but the API calls to API Gateway fail with 403. This is often due to missing API key. If the API Gateway endpoint requires an API key and the JavaScript code does not include it in the request headers, API Gateway returns a 403 Forbidden error.

Option C is correct because the most likely cause is that the API key is not included in the JavaScript code, leading to the 403 response.

Exam trap

Candidates often confuse CORS issues with API key requirements. While CORS can cause errors, a 403 Forbidden error from API Gateway often indicates that an API key is required but not provided. The trap is to assume it is a CORS problem without checking the API key requirement.

How to eliminate wrong answers

Option A is wrong because the S3 bucket policy controls access to S3 objects, not outbound API calls from JavaScript; the 403 error originates from the browser's CORS enforcement, not from S3 blocking the API Gateway domain. Option B is wrong because the website loads successfully, confirming static website hosting is already enabled; the issue is with cross-origin API calls, not S3 hosting configuration. Option C is wrong because API keys are optional for API Gateway and, if required, would cause a 403 from API Gateway itself (e.g., 'Missing Authentication Token'), not a browser-level CORS 403; the error is due to missing CORS headers, not missing API keys.

172
MCQmedium

A company is using Amazon S3 to store sensitive documents. The security team requires that all data be encrypted at rest using AWS KMS with a Customer Managed Key (CMK). The developer enabled default encryption on the S3 bucket with the CMK. However, some PUT requests are failing with 'Access Denied'. What is the MOST likely cause?

A.The S3 bucket's object ownership is set to BucketOwnerPreferred.
B.The KMS key policy does not grant the IAM user/role permissions to use the key.
C.The KMS key is in a different AWS Region than the S3 bucket.
D.The S3 bucket policy denies PutObject without encryption.
AnswerB

When an IAM user or role attempts to upload an object to S3 using server-side encryption with AWS KMS (SSE-KMS), S3 makes a request to AWS KMS on behalf of the uploader to generate a data key. This operation specifically requires the IAM principal to have `kms:GenerateDataKey` permissions on the specified AWS KMS key. If the KMS key policy does not explicitly allow or implicitly denies this action for the calling principal, the `PutObject` request will fail with an `Access Denied` error because S3 cannot obtain the necessary encryption key from KMS.

Why this answer

When default encryption is enabled on an S3 bucket with a KMS CMK, the S3 service uses the CMK to encrypt objects at rest. However, the IAM user or role making the PUT request must have explicit permissions to use that CMK, typically via the kms:GenerateDataKey and kms:Decrypt actions in the KMS key policy. If the key policy does not grant these permissions to the principal, the request fails with an 'Access Denied' error, even though the bucket policy and IAM permissions are otherwise correct.

Exam trap

The trap here is that candidates often assume enabling default encryption on the bucket is sufficient, overlooking that the IAM principal must also be explicitly authorized to use the KMS key via the key policy or IAM policy.

How to eliminate wrong answers

Option A is wrong because S3 bucket object ownership (BucketOwnerPreferred) controls whether objects uploaded by other AWS accounts are owned by the bucket owner, not encryption permissions; it does not cause 'Access Denied' on PUT requests when using a CMK. Option C is wrong because KMS keys are regional resources, and S3 buckets can only use KMS keys from the same region as the bucket; if the key were in a different region, the bucket configuration would fail at setup, not cause intermittent PUT failures. Option D is wrong because a bucket policy denying PutObject without encryption would cause failures for unencrypted requests, but the developer has already enabled default encryption with the CMK, so requests are encrypted; the error is due to KMS key permissions, not encryption enforcement.

173
Multi-Selecteasy

A developer is troubleshooting an AWS Lambda function that is timing out. The function is configured with a 3-second timeout. Which of the following could cause the function to timeout? (Choose THREE.)

Select 3 answers
A.The function's reserved concurrency is set to 0.
B.The function has a dead-letter queue configured.
C.The function is configured to access a VPC without a NAT gateway.
D.The function experiences a cold start.
E.The function's deployment package is larger than 50 MB.
AnswersC, D, E

When a Lambda function is configured to access a VPC but lacks a NAT gateway, outbound internet traffic fails. If the function makes external calls (e.g., to DynamoDB or external APIs), these requests will hang until the function times out.

Why this answer

Lambda timeouts occur when the function execution exceeds the configured timeout. Option A is incorrect because setting reserved concurrency to 0 causes immediate throttling (TooManyRequestsException), not a timeout. Option B is incorrect because a dead-letter queue is for asynchronous invocation failures, not timeouts.

Option C is correct: if the function is in a VPC without a NAT gateway, it cannot access external networks, leading to network timeouts. Option D is correct: cold starts can delay execution due to initialization, potentially exceeding the timeout. Option E is correct: a deployment package larger than 50 MB can increase cold start time significantly, causing the function to timeout.

Exam trap

Candidates may mistakenly think reserved concurrency of 0 causes a timeout, but it actually causes immediate throttling. The real trap is that cold starts and large deployment packages can both contribute to timeouts, especially when the timeout is short.

174
MCQeasy

A developer wants to invoke an AWS Lambda function every hour to perform a maintenance task. Which AWS service should be used to schedule the invocation?

A.Amazon Simple Queue Service (SQS)
B.AWS Step Functions
C.Amazon CloudWatch Events (EventBridge)
D.Amazon Simple Notification Service (SNS)
AnswerC

Amazon CloudWatch Events, now largely integrated into Amazon EventBridge, is the definitive AWS service for triggering Lambda functions on a schedule. It enables developers to create rules that define specific time-based patterns, such as cron expressions or fixed-rate intervals, to directly invoke target Lambda functions. This provides a robust, serverless, and highly scalable solution for automating periodic tasks and time-driven events within the AWS ecosystem.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) is the correct service for scheduling periodic invocations of AWS Lambda functions. It allows you to create a rule with a cron or rate expression (e.g., `rate(1 hour)`) that triggers the Lambda function on a defined schedule. This is the native, serverless way to run code on a recurring timer without managing any infrastructure.

Exam trap

The trap here is that candidates often confuse 'scheduling' with 'messaging' and pick SQS or SNS, not realizing that only EventBridge (CloudWatch Events) provides native cron/rate-based triggers for Lambda.

How to eliminate wrong answers

Option A is wrong because Amazon SQS is a message queue service for decoupling application components; it does not have a built-in scheduler to invoke Lambda on a recurring schedule. Option B is wrong because AWS Step Functions is a workflow orchestration service that can invoke Lambda, but it is designed for stateful, multi-step processes, not for simple time-based scheduling (it lacks native cron/rate triggers). Option D is wrong because Amazon SNS is a pub/sub notification service; it can trigger Lambda from messages, but it cannot generate scheduled events on its own.

175
MCQeasy

A developer is building a serverless application and wants to invoke an AWS Lambda function every hour to perform a cleanup task. Which AWS service should the developer use to schedule the invocation?

A.AWS Step Functions
B.Amazon SNS
C.Amazon SQS
D.Amazon EventBridge (CloudWatch Events)
AnswerD

Amazon EventBridge, which evolved from CloudWatch Events, is a serverless event bus service that makes it easy to connect applications together using data from your own applications, integrated SaaS applications, and AWS services. It excels at creating rules that match incoming events and route them to targets, including Lambda functions. Crucially, EventBridge supports cron-like expressions and fixed-rate schedules, making it the ideal service for invoking Lambda functions at specified times or recurring intervals.

Why this answer

Amazon EventBridge (formerly CloudWatch Events) is the correct service for scheduling AWS Lambda invocations on a recurring basis. It provides a cron or rate expression to trigger a Lambda function at a defined interval, such as every hour, without the need for managing any servers or additional infrastructure.

Exam trap

The trap here is that candidates often confuse Amazon EventBridge with Amazon CloudWatch Logs or assume Step Functions is needed for any time-based workflow, but Step Functions is for stateful orchestration, not simple scheduled invocations.

How to eliminate wrong answers

Option A is wrong because AWS Step Functions is a workflow orchestration service designed to coordinate multiple AWS services into state machines, not for scheduling standalone recurring events. Option B is wrong because Amazon SNS is a pub/sub messaging service for sending notifications or fan-out messages, not a scheduler for invoking Lambda on a time-based trigger. Option C is wrong because Amazon SQS is a message queue service for decoupling application components; it cannot initiate Lambda invocations based on a time schedule.

176
MCQhard

A company is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails with the error 'The overall deployment failed because too many individual instances failed to deploy.' The CodeDeploy agent logs show that the BeforeInstall lifecycle event script returned a non-zero exit code. What is the MOST likely cause of this issue?

A.The application revision is missing from the S3 bucket.
B.The BeforeInstall script has a bug that causes it to exit with a non-zero status.
C.The IAM instance profile does not have permissions to call CodeDeploy APIs.
D.The CodeDeploy agent is not running on the instances.
AnswerB

CodeDeploy strictly interprets any non-zero exit status from a lifecycle event script, such as BeforeInstall, as a critical failure. This indicates that the script, intended to prepare the environment or install prerequisites, did not complete successfully. Consequently, the deployment on that specific instance is immediately halted, and the overall deployment is marked as failed, preventing further potentially problematic steps.

Why this answer

The error message explicitly states that the CodeDeploy agent logs show the BeforeInstall lifecycle event script returned a non-zero exit code. This directly indicates that the script itself failed during execution, which is the most likely cause of the deployment failure. The BeforeInstall script is a custom script run by the CodeDeploy agent on each instance, and a non-zero exit code signals an error condition that halts the deployment for that instance.

Exam trap

The trap here is that candidates often confuse a script failure (non-zero exit code) with infrastructure or permission issues, but the question explicitly provides the agent log detail pointing to the BeforeInstall script, making the script bug the direct and most likely cause.

How to eliminate wrong answers

Option A is wrong because if the application revision were missing from the S3 bucket, the error would occur earlier in the process (during the download phase) and the CodeDeploy agent logs would show a different error, such as 'Failed to download revision' or a 403/404 HTTP status code, not a non-zero exit code from the BeforeInstall script. Option C is wrong because insufficient IAM instance profile permissions to call CodeDeploy APIs would prevent the agent from registering with the service or pulling deployment instructions, resulting in errors like 'Unable to register instance' or 'AccessDeniedException', not a script exit code failure. Option D is wrong because if the CodeDeploy agent were not running, the instances would not appear in the deployment at all, and the error would be 'No instances found' or 'Instance not available', not a script execution failure with a non-zero exit code.

177
MCQmedium

A developer is building a RESTful API using Amazon API Gateway and Lambda. The API should support CORS for a specific origin (https://example.com) and allow only GET and POST methods. Which configuration in the OPTIONS method response will satisfy these requirements?

A.Access-Control-Allow-Origin: https://example.com, Access-Control-Allow-Methods: GET,POST
B.Access-Control-Allow-Origin: *, Access-Control-Allow-Methods: GET,POST,OPTIONS
C.Access-Control-Allow-Origin: https://example.com, Access-Control-Allow-Methods: GET,POST,OPTIONS
D.Access-Control-Allow-Origin: https://example.com, Access-Control-Allow-Headers: Content-Type
AnswerA

This configuration correctly specifies `https://example.com` as the only permitted origin, adhering to the principle of least privilege for cross-origin requests. By listing `GET,POST` in `Access-Control-Allow-Methods`, the server explicitly informs the browser which actual HTTP methods are allowed for the resource, satisfying the preflight request's requirements without exposing unnecessary methods like `OPTIONS` itself.

Why this answer

The OPTIONS method response must include the `Access-Control-Allow-Origin` header set to the specific origin `https://example.com` to restrict CORS access, and the `Access-Control-Allow-Methods` header must list only the allowed HTTP methods (`GET,POST`). The OPTIONS method itself is a preflight request and does not need to be listed in the allowed methods; it is automatically handled by the browser. This configuration satisfies the requirement of supporting CORS for a single origin and only GET and POST methods.

Exam trap

The trap here is that candidates often mistakenly include `OPTIONS` in the `Access-Control-Allow-Methods` header, thinking it must be listed because the preflight request uses that method, but the correct behavior is to only list the actual HTTP methods (GET, POST) that the API supports for the main request.

How to eliminate wrong answers

Option B is wrong because it uses a wildcard origin (`*`), which does not satisfy the requirement for a specific origin (`https://example.com`), and it incorrectly includes `OPTIONS` in the allowed methods list, which is unnecessary and could cause confusion. Option C is wrong because it includes `OPTIONS` in the `Access-Control-Allow-Methods` header; the OPTIONS method is the preflight request itself and should not be listed as an allowed method in the response. Option D is wrong because it specifies `Access-Control-Allow-Headers` instead of `Access-Control-Allow-Methods`, and it omits the required `Access-Control-Allow-Methods` header entirely, so the browser would not know which HTTP methods are permitted.

178
MCQeasy

A developer is creating a CI/CD pipeline for a serverless application using AWS CodePipeline. The application consists of an AWS Lambda function, an Amazon API Gateway REST API, and an Amazon DynamoDB table. Which action should the developer take to automate the deployment of the API Gateway updates?

A.Use AWS Lambda to update the API Gateway configuration.
B.Store the API Gateway Swagger file in Amazon S3 and trigger a deployment.
C.Use AWS CloudFormation to define and deploy the API Gateway.
D.Use AWS CodeBuild to compile and deploy the API Gateway configuration.
AnswerC

AWS CloudFormation is the recommended and most robust service for defining and deploying AWS resources, including API Gateway, as Infrastructure as Code (IaC). It allows developers to declaratively specify the entire API Gateway configuration in a template, enabling automated, repeatable, and version-controlled deployments with built-in rollback capabilities, which is crucial for maintaining consistency and reliability in CI/CD pipelines.

Why this answer

AWS CloudFormation provides infrastructure as code (IaC) capabilities that allow you to define the entire API Gateway configuration, including resources, methods, integrations, and deployment stages, in a template. When integrated with CodePipeline, CloudFormation can automatically create or update the API Gateway and trigger a deployment as part of the CI/CD pipeline, ensuring consistent and repeatable deployments without manual intervention.

Exam trap

The trap here is that candidates often assume CodeBuild or a custom Lambda function is needed for deployment, but the exam tests whether you recognize that CloudFormation is the native, fully managed IaC service that integrates seamlessly with CodePipeline for deploying API Gateway updates.

How to eliminate wrong answers

Option A is wrong because using a Lambda function to update API Gateway configuration directly via API calls is not a recommended or scalable CI/CD practice; it bypasses infrastructure as code, lacks versioning, and makes rollbacks and auditing difficult. Option B is wrong because simply storing a Swagger file in S3 does not automatically trigger a deployment; you would need additional automation (e.g., a Lambda function or CloudFormation) to import the Swagger definition and create a deployment, making this an incomplete solution. Option D is wrong because CodeBuild is designed to compile source code and run tests, not to deploy API Gateway configurations; it lacks the native capability to manage API Gateway resources and deployments, which is better handled by CloudFormation or the AWS CLI.

179
MCQmedium

A developer is deploying a web application on AWS Elastic Beanstalk. The application requires a fixed IP address for outbound traffic to a third-party API. What is the MOST cost-effective solution?

A.Launch the environment in a VPC with a NAT Gateway in a public subnet.
B.Attach an Internet Gateway to the VPC.
C.Use a VPC endpoint for the third-party API.
D.Assign an Elastic IP to each EC2 instance.
AnswerA

This is the correct approach for instances in private subnets needing outbound internet access to third-party APIs while maintaining private IP addresses. A NAT Gateway, deployed in a public subnet, allows instances in private subnets to initiate outbound connections to the internet. All outbound traffic from these private instances will appear to originate from the NAT Gateway's Elastic IP address, providing a consistent and fixed public IP for the third-party API to whitelist, which is crucial for security policies.

Why this answer

A NAT Gateway in a public subnet provides a fixed public IP address for outbound traffic from private subnets, enabling the web application to communicate with the third-party API while remaining secure. Elastic Beanstalk environments are typically launched in private subnets, and the NAT Gateway is the most cost-effective managed service for this purpose compared to a NAT instance or assigning Elastic IPs to each EC2 instance.

Exam trap

The trap here is that candidates often confuse a NAT Gateway with an Internet Gateway, thinking the latter provides outbound IPs, or they incorrectly assume a VPC endpoint can be used for any external API, when it is limited to AWS services.

How to eliminate wrong answers

Option B is wrong because an Internet Gateway only allows inbound and outbound traffic to and from the internet for resources with public IPs; it does not provide a fixed outbound IP for instances in private subnets. Option C is wrong because a VPC endpoint is used for private connectivity to AWS services (e.g., S3, DynamoDB) via the AWS network, not for accessing third-party APIs over the internet. Option D is wrong because assigning an Elastic IP to each EC2 instance is not cost-effective (each Elastic IP incurs charges when not associated with a running instance) and does not scale well; it also exposes instances directly to the internet, increasing security risks.

180
MCQeasy

A developer is writing an AWS Lambda function that processes messages from an Amazon SQS queue. The function should process each message at least once, but duplicates are acceptable. The function is triggered by a Lambda event source mapping. If the function returns an error, what happens to the message?

A.The message is sent to a dead-letter queue (DLQ).
B.The message is deleted from the queue to prevent duplicate processing.
C.Lambda automatically retries the function with a 1-minute delay.
D.The message remains in the queue and becomes visible after the visibility timeout expires.
AnswerD

When an AWS Lambda function fails to process a message from an SQS queue, the Lambda service does not delete the message. Instead, the message remains in the SQS queue, but it stays hidden from other consumers due to the in-flight visibility timeout that was initiated when Lambda received it. Upon the expiration of this visibility timeout, the message automatically becomes visible again in the queue, making it available for another Lambda invocation attempt or consumption by another service.

Why this answer

When a Lambda function invoked by an SQS event source mapping returns an error, the message is not deleted from the queue. Instead, it remains in the queue and becomes visible again after the visibility timeout expires. This allows the function to retry processing the message, ensuring at-least-once processing.

The default behavior is to retry based on the queue's redrive policy, not to immediately send the message to a DLQ or delete it.

Exam trap

The trap here is that candidates often assume Lambda automatically deletes failed messages or immediately sends them to a DLQ, but the actual behavior is that the message remains in the queue and becomes visible again after the visibility timeout expires, allowing for retries.

How to eliminate wrong answers

Option A is wrong because a message is only sent to a dead-letter queue (DLQ) after the maximum number of retries specified in the queue's redrive policy is exhausted, not on the first error. Option B is wrong because Lambda does not delete a message from the queue on error; deletion only occurs after successful processing to prevent duplicate processing. Option C is wrong because Lambda does not automatically retry with a fixed 1-minute delay; the retry timing is controlled by the SQS visibility timeout, which is configurable and not set to 1 minute by default.

181
MCQmedium

A developer is building a mobile backend using Amazon API Gateway and AWS Lambda. The API has a single endpoint that accepts POST requests with a JSON payload and stores the data in an Amazon DynamoDB table. The developer wants to implement caching to reduce latency and costs. The data is user-specific and should not be shared between users. The developer configures API Gateway caching with a TTL of 300 seconds. After testing, the developer notices that users are seeing other users' data. What should the developer do to fix this issue?

A.Enable cache key parameters in API Gateway, such as the Authorization header.
B.Store cached responses in DynamoDB and retrieve them based on user ID.
C.Use Lambda@Edge to cache responses at the CloudFront level.
D.Disable API Gateway caching and use DynamoDB Accelerator (DAX) instead.
AnswerA

API Gateway's caching mechanism allows developers to specify request parameters, such as headers, query strings, or path parameters, to be included in the cache key. By enabling the Authorization header as a cache key parameter, API Gateway generates a unique cache entry for each distinct Authorization token presented by a user. This ensures that responses are cached on a per-user basis, preventing data leakage between users while still providing the performance benefits of caching for repeated requests from the same authenticated user.

Why this answer

API Gateway caching by default uses only the request path and method as the cache key, so all POST requests to the same endpoint share a single cache entry. Since the data is user-specific, the cache must include a unique user identifier in the cache key. Enabling cache key parameters (e.g., the Authorization header or a custom user ID header) ensures that each user's request generates a distinct cache key, preventing cross-user data leakage.

This is the correct and minimal fix because it directly addresses the root cause—the cache key not being user-specific—while retaining the performance benefits of API Gateway caching.

Exam trap

DVA-C02 often tests the misconception that enabling API Gateway caching automatically isolates data per user, when in fact the default cache key only includes the method and path, leading to cross-user data leakage unless cache key parameters are explicitly configured.

How to eliminate wrong answers

Option B is wrong because storing cached responses in DynamoDB and retrieving them by user ID is a custom application-level caching solution that adds complexity, cost, and latency; it does not fix the API Gateway cache misconfiguration and would still leave the API Gateway cache leaking data unless disabled. Option C is wrong because Lambda@Edge caches at CloudFront edge locations, but API Gateway caching is separate and still active; moreover, Lambda@Edge is not designed for per-user caching of POST responses and would not solve the issue without also fixing API Gateway. Option D is wrong because disabling API Gateway caching and using DAX only accelerates DynamoDB reads; it does not provide response caching for the API endpoint and would not address the requirement to cache the API response while keeping user data isolated.

182
Multi-Selecteasy

A developer is building a serverless application that uses Amazon S3 for static website hosting and AWS Lambda for dynamic API calls. The developer wants to enable logging of all API requests. Which TWO services can be used to log API requests? (Choose TWO.)

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.VPC Flow Logs
D.Amazon S3 server access logs
E.Amazon Route 53 logs
AnswersA, B

Amazon CloudWatch Logs is the primary service for collecting and monitoring logs from various AWS services and custom applications. For a serverless application utilizing API Gateway, CloudWatch Logs captures detailed execution logs, including request/response payloads, latency, and error messages. These logs are essential for real-time monitoring, debugging, and troubleshooting the runtime behavior of the API Gateway and integrated backend Lambda functions. Configuring API Gateway to send its access and execution logs to CloudWatch Logs provides granular insights into every API call.

Why this answer

Amazon CloudWatch Logs is correct because it can capture and store logs from AWS Lambda function executions. When a Lambda function is invoked via an API request (e.g., through Amazon API Gateway), the function's execution details, including request IDs, timestamps, and error messages, are automatically sent to CloudWatch Logs. This enables developers to monitor and troubleshoot API-driven serverless applications.

Exam trap

The trap here is that candidates often confuse S3 server access logs (which log S3 bucket operations) with API request logging, or mistakenly think VPC Flow Logs can capture HTTP-level API calls when they only capture network-layer traffic.

183
MCQhard

A developer is deploying a microservices architecture on Amazon ECS using Fargate launch type. The services need to communicate with each other. The developer wants to use service discovery so that services can find each other by name. Which AWS service should the developer use?

A.Amazon Route 53 private hosted zones
B.Amazon ECR
C.Application Load Balancer
D.AWS Cloud Map
AnswerD

AWS Cloud Map is the correct choice because it provides a fully managed service discovery solution that allows microservices to locate each other dynamically. It integrates natively with Amazon ECS, automatically registering and deregistering service instances as they scale up or down. This enables applications to discover service endpoints using either API calls or DNS queries, simplifying inter-service communication in a dynamic containerized environment.

Why this answer

AWS Cloud Map is the correct choice because it is a cloud resource discovery service that allows microservices to register their DNS names and health checks, enabling dynamic service discovery. With Amazon ECS and Fargate, services can use AWS Cloud Map namespaces (either API-based or DNS-based) to resolve each other by logical service names, which is essential for inter-service communication in a microservices architecture.

Exam trap

The trap here is that candidates often confuse Route 53 private hosted zones with AWS Cloud Map, not realizing that Cloud Map provides the dynamic registration and health check integration needed for ephemeral containers, whereas Route 53 alone requires manual record management.

How to eliminate wrong answers

Option A is wrong because Amazon Route 53 private hosted zones provide DNS resolution within a VPC but lack the dynamic service registration, health checking, and API-based discovery features that AWS Cloud Map offers for ephemeral Fargate tasks. Option B is wrong because Amazon ECR is a container image registry used for storing and retrieving Docker images, not for service discovery or DNS resolution. Option C is wrong because an Application Load Balancer distributes incoming traffic to targets but does not provide service discovery by name; it is a load balancing layer, not a naming or registration service.

184
Multi-Selectmedium

A developer is implementing a solution to store application logs from multiple EC2 instances. The logs must be stored in a centralized location for analysis. Which services can the developer use to achieve this? (Choose TWO.)

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.Amazon Kinesis Data Analytics
D.Amazon DynamoDB
E.Amazon S3
AnswersA, E

Amazon CloudWatch Logs is a highly scalable and durable service specifically designed for collecting, monitoring, and storing log data from various sources, including EC2 instances, containers, and serverless functions. It provides real-time monitoring, search capabilities, and the ability to set up alarms based on log patterns, making it ideal for operational visibility and troubleshooting application issues. Logs can be retained for specified periods or archived to S3 for long-term storage.

Why this answer

Amazon CloudWatch Logs is correct because it provides a centralized service for collecting, monitoring, and storing log data from EC2 instances. By installing the CloudWatch Logs agent on each EC2 instance, logs are automatically streamed to CloudWatch Logs, where they can be analyzed, searched, and retained for auditing or troubleshooting.

Exam trap

The trap here is that candidates often confuse CloudTrail (which logs AWS API calls) with CloudWatch Logs (which stores application and system logs), leading them to incorrectly select CloudTrail as a solution for application log centralization.

185
MCQhard

A service publishes order events to SNS. Several consumers need different filtered subsets of events without changing publisher code. What should the developer configure?

A.Separate AWS accounts for each consumer
B.Lambda code that discards unwanted events after invocation
C.SNS subscription filter policies
D.SQS long polling only
AnswerC

SNS subscription filter policies are the most direct and efficient solution for this requirement. These policies allow each subscriber to define specific rules based on message attributes or the message body. Only messages that fully match a subscriber's defined filter policy are delivered to that particular endpoint, ensuring consumers receive only the relevant "order events" they need. This prevents unnecessary message delivery and optimizes downstream processing by filtering at the source.

Why this answer

SNS subscription filter policies allow each consumer to define a JSON policy on their subscription that selectively delivers only messages matching specified attributes (e.g., event type, region). This enables multiple consumers to receive different filtered subsets of the same SNS topic without modifying the publisher's code, as the filtering happens server-side at the SNS service level.

Exam trap

The trap here is that candidates often confuse client-side filtering (Option B) with server-side filtering, or assume that SQS long polling (Option D) can filter messages, when in fact SNS subscription filter policies are the only native AWS mechanism for server-side message subsetting without publisher changes.

How to eliminate wrong answers

Option A is wrong because separate AWS accounts do not provide message filtering; they would require duplicating the SNS topic and publisher logic across accounts, adding complexity without solving the subset requirement. Option B is wrong because discarding unwanted events in Lambda after invocation wastes compute resources and incurs unnecessary costs, as the Lambda function is still triggered for every message, defeating the purpose of server-side filtering. Option D is wrong because SQS long polling only controls how often the consumer polls for messages, not which messages are delivered; it does not filter message content or attributes.

186
MCQeasy

A developer is building a serverless REST API using Amazon API Gateway and AWS Lambda. The API will be consumed by a web application hosted on a different domain. The developer needs to enable Cross-Origin Resource Sharing (CORS) for all HTTP methods. What is the most efficient way to achieve this?

A.Enable CORS on the API Gateway resource using the 'Enable CORS' feature in the API Gateway console, which adds the OPTIONS method and appropriate headers.
B.In the Lambda function code, add the 'Access-Control-Allow-Origin' header to every response.
C.Configure Amazon CloudFront in front of API Gateway to handle CORS.
D.Set a bucket policy on the S3 bucket that hosts the web application to allow cross-origin requests.
AnswerA

Enabling CORS directly on the API Gateway resource is the correct and most efficient solution. API Gateway's built-in CORS feature automatically configures the necessary preflight OPTIONS method for the resource. It also injects the required Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers into the method responses and integration responses, ensuring browsers can successfully make cross-origin requests to your API.

Why this answer

API Gateway's 'Enable CORS' feature automatically creates an OPTIONS method for the selected resource and configures the necessary response headers (e.g., Access-Control-Allow-Origin, Access-Control-Allow-Methods, Access-Control-Allow-Headers) to handle preflight requests. This is the most efficient approach as it centralizes CORS configuration at the API Gateway layer, eliminating the need for manual header management in Lambda or additional infrastructure.

Exam trap

The trap here is that candidates assume adding CORS headers only in the Lambda function code is sufficient, overlooking the mandatory preflight OPTIONS request that API Gateway must handle separately.

How to eliminate wrong answers

Option B is wrong because while adding headers in Lambda is necessary for the actual response, it does not handle the preflight OPTIONS request that browsers send before cross-origin requests; without a proper OPTIONS response, CORS will fail. Option C is wrong because CloudFront does not natively handle CORS preflight requests; it can pass through headers but still requires the origin (API Gateway) to be properly configured for CORS, making it an unnecessary extra layer. Option D is wrong because S3 bucket policies control access to S3 objects, not API Gateway endpoints; CORS for the API must be configured on the API Gateway resource itself, not on the web application's hosting bucket.

187
MCQhard

A developer is building an application that uses Amazon DynamoDB as a data store. The application reads the same item frequently but writes rarely. The developer wants to reduce read costs. Which DynamoDB feature should the developer use?

A.DynamoDB Accelerator (DAX)
B.DynamoDB Global Tables
C.DynamoDB Auto Scaling
D.Time to Live (TTL)
AnswerA

DynamoDB Accelerator (DAX) is an in-memory cache designed to provide microsecond response times for read-heavy workloads, significantly reducing the number of read capacity units (RCUs) consumed from the underlying DynamoDB table. When an application reads data through DAX, if the item is in the cache, it's served directly, bypassing DynamoDB and incurring no RCU cost. This makes DAX highly effective for applications requiring low-latency access to frequently read data, directly lowering operational costs associated with read throughput.

Why this answer

DynamoDB Accelerator (DAX) is an in-memory cache that reduces read latency from single-digit milliseconds to microseconds. Since the application reads the same item frequently but writes rarely, DAX can serve repeated read requests from its cache, significantly reducing the number of read capacity units consumed against the DynamoDB table and thus lowering read costs.

Exam trap

The trap here is that candidates often confuse DAX with ElastiCache or assume that Auto Scaling reduces costs, but DAX is the only DynamoDB-native service that directly reduces read costs by caching frequently accessed items.

How to eliminate wrong answers

Option B is wrong because Global Tables provide multi-region replication for disaster recovery and low-latency writes, not read cost reduction. Option C is wrong because Auto Scaling adjusts provisioned throughput based on traffic patterns but does not reduce per-read costs; it only prevents throttling. Option D is wrong because Time to Live (TTL) automatically expires old items to reduce storage costs, not read costs.

188
MCQhard

A company runs a containerized application on Amazon ECS using the Fargate launch type. The application needs to store temporary data that must persist across container restarts but does not need to be shared across multiple tasks. The data should be automatically deleted when the task stops. Which storage option should the developer use?

A.Attach an Amazon EBS volume to the task.
B.Use the ephemeral storage provided by Fargate.
C.Mount an Amazon EFS file system to the container.
D.Create a Docker volume using the 'tmpfs' driver.
AnswerB

Fargate tasks are provisioned with a certain amount of ephemeral storage, typically 20 GB by default, which is local to the task's underlying compute environment. This storage is designed for temporary data, such as application logs, caches, or scratch space, and persists for the entire lifecycle of the Fargate task. While it is deleted once the task stops, it remains available and consistent across restarts of individual containers within that same task, making it suitable for short-lived data that doesn't require long-term persistence.

Why this answer

Fargate provides ephemeral storage (up to 20 GB by default) that persists data across container restarts within the same task but is automatically deleted when the task stops. This matches the requirement for temporary data that does not need to be shared across tasks and is cleaned up upon task termination.

Exam trap

The trap here is that candidates confuse 'persist across container restarts' with 'persist across task stops,' leading them to choose Amazon EFS or EBS, which are designed for long-term persistence, while Fargate's ephemeral storage perfectly meets the temporary, task-scoped requirement.

How to eliminate wrong answers

Option A is wrong because Amazon EBS volumes cannot be directly attached to Fargate tasks; EBS volumes are only supported with EC2 launch type and require instance-level attachment, not task-level. Option C is wrong because Amazon EFS provides persistent, shared file storage that persists beyond the task lifecycle and is designed for multi-task sharing, which contradicts the requirement for data to be automatically deleted when the task stops. Option D is wrong because Docker volumes using the 'tmpfs' driver store data in memory, not on disk, and do not persist across container restarts; they are ephemeral and lost when the container stops.

189
MCQhard

A developer is deploying a web application on Amazon EKS. The application needs to read configuration data from an Amazon S3 bucket at startup. The developer wants to ensure that the configuration is securely accessed without embedding AWS credentials in the application code. Which solution should the developer use?

A.Use IAM roles for service accounts (IRSA) to assign an IAM role to the pod.
B.Store the AWS credentials in AWS Secrets Manager and retrieve them at startup.
C.Assign an IAM instance profile to the EC2 instances running the EKS nodes.
D.Embed the AWS access key and secret key in a Kubernetes ConfigMap.
AnswerA

IAM roles for service accounts (IRSA) is the recommended and most secure method for granting AWS permissions to applications running in EKS pods. It leverages an OpenID Connect (OIDC) provider associated with the EKS cluster to allow Kubernetes service accounts to assume specific IAM roles. This mechanism provides fine-grained, pod-level permissions, ensuring that each pod receives only the necessary temporary AWS credentials, thereby adhering strictly to the principle of least privilege and enhancing overall security.

Why this answer

IAM roles for service accounts (IRSA) allows you to associate an IAM role with a Kubernetes service account, which the pod can assume to obtain temporary AWS credentials via the AWS STS endpoint. This eliminates the need to embed long-term credentials in the application code or environment variables, and the credentials are automatically rotated by the AWS SDK. The pod retrieves the configuration from S3 using the assumed role's permissions, ensuring secure access.

Exam trap

The trap here is that candidates may confuse IRSA with IAM instance profiles, thinking that assigning a role to the node is sufficient, but IRSA is the correct method for pod-level IAM permissions in EKS.

How to eliminate wrong answers

Option B is wrong because storing AWS credentials in AWS Secrets Manager still requires the application to retrieve them at startup, which introduces a credential management overhead and a potential attack surface if the retrieval itself is not secured; it does not eliminate the need to handle long-term credentials. Option C is wrong because assigning an IAM instance profile to the EC2 nodes grants permissions to all pods running on those nodes, violating the principle of least privilege and potentially allowing unintended access to the S3 bucket. Option D is wrong because embedding AWS access keys in a Kubernetes ConfigMap exposes the credentials in plaintext within the cluster, which is a severe security risk and violates AWS best practices.

190
MCQeasy

A developer needs to store application configuration settings that may change at runtime and wants to avoid redeploying the application. Which AWS service should be used?

A.AWS Systems Manager Parameter Store
B.AWS Secrets Manager
C.Amazon DynamoDB
D.AWS AppConfig
AnswerD

AWS AppConfig is purpose-built for managing and deploying application configurations dynamically and safely across various environments. It provides robust features such as configuration validation against a schema, staged rollouts (e.g., linear, canary deployments) to gradually expose changes, and automatic rollback capabilities if errors are detected. This ensures that configuration changes are applied reliably without requiring code deployments or service restarts, minimizing impact on end-users and maintaining application stability.

Why this answer

AWS AppConfig is purpose-built for managing application configuration that changes at runtime, supporting feature flags, dynamic configuration, and safe deployments with validation and rollback. It allows applications to fetch configuration via the AppConfig agent or API without redeploying, and integrates with CloudWatch alarms for automatic rollback on errors.

Exam trap

DVA-C02 often tests the confusion between Parameter Store (static config/secrets) and AppConfig (dynamic runtime config with safe deployment) — candidates must recognize that 'changes at runtime without redeployment' points to AppConfig.

How to eliminate wrong answers

Option A is wrong because Systems Manager Parameter Store is designed for static configuration values and secrets, not for runtime feature flags with safe deployment and validation — it lacks AppConfig's gradual rollout and automatic rollback capabilities. Option B is wrong because Secrets Manager is specifically for storing and rotating secrets (database credentials, API keys), not general application configuration that changes at runtime. Option C is wrong because DynamoDB is a NoSQL database for application data storage, not a configuration management service — using it for config requires custom polling logic and lacks validation/rollback features.

191
MCQhard

A company runs a critical application on AWS Lambda that processes real-time data from Kinesis Data Streams. The function is idempotent, but occasionally duplicate records are processed due to retries. The company wants to ensure exactly-once processing. Which approach should the developer implement?

A.Use an SQS FIFO queue between Kinesis and Lambda.
B.Use a DynamoDB table to store processed record IDs and perform deduplication in the Lambda function.
C.Enable Lambda reserved concurrency to limit retries.
D.Reduce the batch size in the event source mapping.
AnswerB

Implementing a deduplication mechanism within the Lambda function using a DynamoDB table is the standard and most effective approach for achieving exactly-once processing semantics from Kinesis. The Lambda function can store a unique identifier for each processed record (e.g., a combination of Kinesis shard ID and sequence number) in a DynamoDB table. Before processing a new record, the function checks if its ID already exists in DynamoDB; if so, it skips processing, ensuring that even if Kinesis retries delivery, the record's side effects occur only once.

Why this answer

DynamoDB provides a scalable, low-latency store for tracking processed record IDs, enabling the Lambda function to check for duplicates before processing. Since the function is idempotent but retries cause duplicates, a DynamoDB-based deduplication layer ensures exactly-once semantics without altering the event source or introducing ordering constraints.

Exam trap

The trap here is that candidates often assume SQS FIFO queues guarantee exactly-once processing end-to-end, but they overlook that Kinesis itself does not provide exactly-once delivery, so duplicates can still originate from the stream before reaching the queue.

How to eliminate wrong answers

Option A is wrong because inserting an SQS FIFO queue between Kinesis and Lambda does not eliminate duplicates from Kinesis itself; Kinesis can still deliver the same record multiple times, and SQS FIFO does not deduplicate across different message groups or handle Kinesis-level retries. Option C is wrong because Lambda reserved concurrency limits the number of concurrent executions but does not prevent duplicate records from being processed; retries can still occur within the same or different invocations. Option D is wrong because reducing the batch size in the event source mapping reduces the number of records per invocation but does not prevent Kinesis from redelivering the same record on retries, so duplicates persist.

192
MCQmedium

A developer is using AWS CodePipeline to automate deployments. The pipeline has a manual approval action that requires a developer to approve before deploying to production. The developer wants to receive an email notification when an approval action is pending. Which AWS service should be used to send the notification?

A.Amazon Simple Email Service (SES)
B.AWS Lambda
C.Amazon Simple Notification Service (SNS)
D.Amazon CloudWatch Logs
AnswerC

Amazon Simple Notification Service (SNS) is a highly scalable, fully managed pub/sub messaging service that enables you to send messages to a large number of subscribers or endpoints. CodePipeline natively integrates with SNS, allowing developers to configure notifications for pipeline state changes, approval actions, or execution failures to an SNS topic. This topic can then reliably deliver these alerts via various protocols, including email, SMS, or to other AWS services, making it the direct and most efficient solution for email notifications.

Why this answer

Amazon Simple Notification Service (SNS) is the correct choice because it is a pub/sub messaging service designed to send notifications to subscribers via email, SMS, or other protocols. CodePipeline can publish events to an SNS topic when an approval action is pending, and the developer can subscribe an email endpoint to that topic to receive the notification directly.

Exam trap

The trap here is that candidates may confuse Amazon SES with SNS because both can send emails, but SES is a dedicated email-sending service requiring manual integration, whereas SNS is the native event notification service that directly integrates with CodePipeline's approval actions.

How to eliminate wrong answers

Option A is wrong because Amazon Simple Email Service (SES) is a platform for sending transactional and marketing emails, but it is not integrated with CodePipeline's event-driven notifications; SES requires explicit API calls or SMTP configuration and does not natively subscribe to CodePipeline events. Option B is wrong because AWS Lambda is a compute service that can process events, but it is not a notification delivery service; while Lambda could be used to send emails via SES, it adds unnecessary complexity and is not the direct service for sending email notifications from a CodePipeline approval action. Option D is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files; it does not send notifications and is not designed for real-time alerting to email endpoints.

193
Multi-Selecteasy

A developer is using AWS Step Functions to orchestrate a workflow. The developer wants to handle errors and retries for a task. Which TWO fields can be used in a state definition to configure error handling? (Choose TWO.)

Select 2 answers
A.Retry
B.Catch
C.FailureState
D.ErrorOutput
E.ErrorAction
AnswersA, B

In AWS Step Functions, the "Retry" field within a state definition allows a developer to specify a retry policy for transient errors. It defines which errors ("ErrorEquals"), how many times ("MaxAttempts"), and with what delay ("IntervalSeconds" and "BackoffRate") the state should be re-executed before failing. This mechanism is crucial for building resilient workflows that can automatically recover from temporary issues without manual intervention.

Why this answer

The `Retry` field in an AWS Step Functions state definition defines an array of retry policies, specifying which errors to retry, the maximum number of retry attempts, the interval between retries, and the backoff rate. Option B is correct because the `Catch` field defines an array of fallback states or state machine transitions that are executed when a specific error occurs after all retry attempts are exhausted, allowing the workflow to handle errors gracefully.

Exam trap

The trap here is that candidates often confuse the `Retry` and `Catch` fields with non-existent fields like `FailureState` or `ErrorAction`, or they mistakenly think `ErrorOutput` is used to capture error details, when in fact Step Functions uses `ResultPath` to include error information in the state output.

194
MCQeasy

A developer is building a web application that requires user authentication. The application will run on Amazon EC2 instances behind an Application Load Balancer. The developer wants to offload authentication to a managed service that supports social login providers. Which AWS service should the developer use?

A.AWS Identity and Access Management (IAM)
B.Amazon Cognito
C.AWS Directory Service
D.AWS Single Sign-On
AnswerB

Amazon Cognito is the correct choice because it is specifically engineered to provide secure and scalable user directories for web and mobile applications. Cognito User Pools enable easy sign-up, sign-in, and access control for application users, supporting multi-factor authentication and integration with social identity providers like Google, Facebook, and Apple. It offloads the complexity of user management and authentication from your application backend.

Why this answer

Amazon Cognito is the correct choice because it is a fully managed identity service designed for web and mobile applications, providing user authentication, authorization, and support for social login providers (e.g., Google, Facebook, Amazon) via OAuth 2.0 and OpenID Connect. It offloads the entire authentication workflow from the EC2 instances and ALB, integrating seamlessly with the ALB's authentication action to validate tokens before traffic reaches the application.

Exam trap

The trap here is that candidates often confuse IAM's role-based access control with user authentication, overlooking that IAM cannot handle social login providers or external user identity federation for customer-facing apps.

How to eliminate wrong answers

Option A is wrong because AWS IAM is for managing AWS service access and permissions for users and roles, not for external user authentication with social login providers; it lacks built-in support for social identity federation. Option C is wrong because AWS Directory Service provides managed Microsoft Active Directory or LDAP-based directories for enterprise identity, which does not natively support social login providers like Google or Facebook. Option D is wrong because AWS Single Sign-On (now AWS IAM Identity Center) is designed for workforce identity and SSO across AWS accounts and business applications, not for customer-facing web app authentication with social logins.

195
MCQmedium

The exhibit shows an IAM policy attached to a user. The user reports being unable to upload files to S3 bucket 'my-bucket'. What is the MOST likely cause?

A.The user needs s3:PutObjectAcl permission
B.The bucket policy denies the upload
C.The policy does not allow s3:ListBucket
D.The user does not have s3:GetObject permission
AnswerB

An explicit `Deny` statement in an S3 bucket policy always takes precedence over any `Allow` statement in an attached IAM user policy, even if the IAM policy grants the necessary `s3:PutObject` permission. AWS's authorization logic dictates that if any policy in the evaluation path contains an explicit deny for a requested action, that action is forbidden, regardless of other allow statements. This ensures that bucket owners maintain ultimate control over their resources.

Why this answer

The user has an IAM policy that grants s3:PutObject on 'my-bucket', but the bucket policy explicitly denies s3:PutObject for that user. Since an explicit deny in a resource-based policy overrides any allow in an identity-based policy, the upload fails. AWS IAM evaluates all policies, and a single explicit deny results in a final decision of deny.

Exam trap

The trap here is that candidates assume an IAM allow is sufficient, forgetting that resource-based policies (like S3 bucket policies) can override with an explicit deny, making the user unable to upload despite having the correct IAM permissions.

How to eliminate wrong answers

Option A is wrong because s3:PutObjectAcl is only needed if the upload request includes a canned ACL or requires modifying object ACLs; the basic upload action s3:PutObject does not require it. Option C is wrong because s3:ListBucket is required for listing objects, not for uploading a single object; the upload action only needs s3:PutObject. Option D is wrong because s3:GetObject is for reading/downloading objects, not for uploading; the user's inability to upload is unrelated to read permissions.

196
MCQmedium

A developer is using Amazon DynamoDB as the data store for a serverless application. The application experiences high read traffic, and the developer wants to reduce latency. The data is not frequently updated. Which DynamoDB feature should the developer use?

A.DynamoDB Auto Scaling
B.DynamoDB Global Tables
C.DynamoDB Accelerator (DAX)
D.DynamoDB Time to Live (TTL)
AnswerC

DynamoDB Accelerator (DAX) is a fully managed, highly available, in-memory cache specifically designed for DynamoDB. It provides microsecond response times for read-heavy workloads by caching items and query results, significantly reducing the load on the underlying DynamoDB table. DAX acts as a transparent proxy, allowing applications to continue using the DynamoDB API while benefiting from accelerated read performance.

Why this answer

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache that reduces read latency for DynamoDB tables from single-digit milliseconds to microseconds. Since the data is not frequently updated, DAX can serve repeated read requests from its cache without hitting the underlying table, making it ideal for high-read, low-write workloads.

Exam trap

The trap here is that candidates may confuse DAX with Global Tables, thinking that replicating data across regions reduces latency, but the question specifies reducing latency within a single region, where DAX's in-memory caching is the correct solution.

How to eliminate wrong answers

Option A is wrong because DynamoDB Auto Scaling adjusts provisioned throughput capacity based on traffic patterns, which helps manage cost and performance but does not reduce read latency. Option B is wrong because DynamoDB Global Tables provide multi-region replication for disaster recovery and low-latency reads across regions, but they do not improve read latency within a single region. Option D is wrong because DynamoDB Time to Live (TTL) automatically deletes expired items to manage storage costs, and has no impact on read performance or latency.

197
Multi-Selecthard

A Lambda function processes a batch of SQS messages. Which two configurations reduce duplicate or failed-message impact?

Select 2 answers
A.Set visibility timeout to zero
B.Use a visibility timeout longer than expected processing time
C.Disable the dead-letter queue
D.Configure a dead-letter queue and partial batch response where appropriate
AnswersB, D

Utilizing an SQS visibility timeout that is longer than the expected message processing time is a fundamental best practice for reliable asynchronous processing. This ensures that once a Lambda function receives a message, it has sufficient exclusive time to process it successfully and delete it from the queue before it becomes visible to other consumers. This prevents duplicate processing attempts and ensures that each message is handled at least once without unnecessary retries by other instances.

Why this answer

A visibility timeout longer than the expected processing time prevents other consumers from reprocessing a message while it is still being handled, reducing duplicates. Option D is correct because a dead-letter queue captures messages that repeatedly fail processing, allowing analysis and preventing them from blocking the queue, while partial batch response enables the function to return a list of failed message IDs so that only those messages become visible again, reducing reprocessing of successful ones.

Exam trap

The trap here is that candidates often think setting visibility timeout to zero or disabling the DLQ simplifies processing, but in reality, these actions increase duplicate or failed-message impact by removing mechanisms that control reprocessing and isolate problematic messages.

198
MCQhard

A developer is using AWS CodeDeploy to deploy a new version of an application to an Auto Scaling group. The deployment fails because the new instances do not pass the health check. The developer wants to automatically roll back the deployment if the health check fails. Which CodeDeploy setting should be configured?

A.Set the deployment configuration to AllAtOnce to speed up the process.
B.Configure a lifecycle hook to terminate failing instances.
C.Use a blue/green deployment strategy instead of in-place.
D.Enable automatic rollback in the deployment group configuration.
AnswerD

Enabling automatic rollback within the CodeDeploy deployment group configuration is the most direct and effective solution for ensuring recovery from problematic deployments. This feature allows CodeDeploy to monitor the health of a new deployment using specified CloudWatch alarms or other health checks. Upon detecting a failure, it automatically reverts all instances in the deployment group to the last known good application revision, minimizing downtime and operational overhead by providing a self-healing mechanism.

Why this answer

AWS CodeDeploy provides a built-in automatic rollback feature that can be configured at the deployment group level. When enabled, if a deployment fails (e.g., due to health check failures), CodeDeploy automatically reverts to the last known successful deployment, ensuring minimal downtime and manual intervention.

Exam trap

The trap here is that candidates often confuse deployment strategies (like blue/green or in-place) with rollback mechanisms, not realizing that rollback is a separate configuration setting that must be explicitly enabled regardless of the deployment strategy.

How to eliminate wrong answers

Option A is wrong because changing the deployment configuration to AllAtOnce does not enable rollback; it only deploys to all instances simultaneously, which could increase the blast radius of a failed deployment. Option B is wrong because lifecycle hooks are used to perform custom actions (e.g., draining connections) during instance launch or termination, not to trigger automatic rollbacks of a deployment. Option C is wrong because while blue/green deployment can reduce risk, it does not inherently provide automatic rollback on health check failure; rollback must be explicitly enabled in the deployment group configuration.

199
MCQeasy

A developer is designing a REST API using Amazon API Gateway that experiences high traffic with many repeated requests for the same data. The developer wants to reduce backend load and improve response times. Which feature should the developer enable on the API Gateway method?

A.Enable API Gateway caching
B.Implement caching in the Lambda function using a local cache
C.Use an Amazon ElastiCache Redis cluster and modify the Lambda function to check the cache first
D.Place an Amazon CloudFront distribution in front of API Gateway
AnswerA

Enabling API Gateway caching directly addresses the problem by storing responses from the backend integration (e.g., Lambda) for a configurable Time-To-Live (TTL). This significantly reduces the number of identical requests that reach the backend service, offloading the compute and database resources. It operates at the API Gateway layer, making it highly efficient for repeated requests to the same API method and improving overall API responsiveness.

Why this answer

API Gateway caching stores responses from backend endpoints for a configurable Time-to-Live (TTL). When a request for the same data arrives, API Gateway serves the cached response directly without invoking the backend, reducing load and improving latency. This is the most straightforward and managed solution for repeated requests at the API layer.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing a distributed cache like ElastiCache or a CDN like CloudFront, when the simplest and most cost-effective managed service (API Gateway caching) directly addresses the requirement at the API layer.

How to eliminate wrong answers

Option B is wrong because implementing a local cache inside a Lambda function is ephemeral and not shared across concurrent invocations, so it cannot reduce backend load for repeated requests from different clients. Option C is wrong because while ElastiCache Redis can cache data, it requires additional code in the Lambda function to check the cache first, adding complexity and latency compared to API Gateway's built-in caching. Option D is wrong because CloudFront caches content at the edge, but it does not reduce backend load for API Gateway itself unless combined with API Gateway caching; CloudFront alone still forwards cache misses to API Gateway, which then invokes the backend.

200
Multi-Selectmedium

A developer is designing a highly available application using Amazon SQS and AWS Lambda. Which TWO strategies should the developer implement to ensure that messages are processed at least once? (Choose TWO.)

Select 2 answers
A.Configure a Dead Letter Queue (DLQ) to capture failed messages.
B.Enable long polling on the SQS queue.
C.Use a FIFO queue to ensure exactly-once processing.
D.Set the SQS queue's visibility timeout to be greater than the Lambda function's timeout.
E.Use the SQS DeleteMessage API inside the Lambda function only after successful processing.
AnswersD, E

Setting the SQS queue's visibility timeout to be greater than the Lambda function's timeout is crucial for at-least-once processing. If the Lambda function fails or times out before successfully processing and deleting a message, the message will automatically become visible again in the queue once the SQS visibility timeout expires. This ensures that another consumer or a subsequent invocation of the Lambda function can pick up and re-process the message, guaranteeing it is processed at least once.

Why this answer

Setting the SQS queue's visibility timeout to be greater than the Lambda function's timeout ensures that if the Lambda function fails or times out, the message becomes visible again in the queue after the visibility timeout expires, allowing another consumer to retry processing. This prevents messages from being lost due to processing failures, supporting at-least-once processing. Option E is correct because calling the SQS DeleteMessage API only after successful processing ensures that the message is not removed from the queue until it has been fully and correctly handled, so if processing fails, the message remains available for retry.

Exam trap

The trap here is that candidates often confuse the purpose of a Dead Letter Queue (DLQ) as a mechanism for ensuring at-least-once processing, when in fact it is for isolating messages that have exhausted retries, not for guaranteeing delivery.

201
MCQeasy

A developer is building a serverless application using AWS Lambda. The function needs to access an S3 bucket to read a configuration file. What is the best way to provide the Lambda function with the bucket name?

A.Hardcode the bucket name in the Lambda function code.
B.Store the bucket name in an environment variable for the Lambda function.
C.Read the bucket name from a text file stored in the same bucket.
D.Use a KMS key to encrypt the bucket name and decrypt it in the function.
AnswerB

Storing the S3 bucket name in an environment variable is the recommended and most efficient method for passing configuration data to an AWS Lambda function. Environment variables are easily configured through the AWS Management Console, CLI, or Infrastructure as Code tools like CloudFormation or Terraform, allowing updates without modifying or redeploying the function's code. This promotes separation of configuration from code, enhances flexibility across different deployment environments, and improves operational agility.

Why this answer

AWS Lambda environment variables provide a secure, configurable, and decoupled way to pass the S3 bucket name to the function without hardcoding it in the code. This follows the principle of infrastructure as code and allows the same function code to be reused across different environments (e.g., dev, staging, prod) by simply changing the environment variable value. Environment variables are encrypted at rest by default using AWS KMS, ensuring the bucket name is not exposed in plaintext within the code repository.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing KMS encryption (Option D) or the circular dependency of reading from the same bucket (Option C), when the simplest and most secure approach—environment variables—is the correct answer for decoupling configuration from code.

How to eliminate wrong answers

Option A is wrong because hardcoding the bucket name in the Lambda function code violates the separation of configuration from code, making the function environment-specific and requiring code changes to point to a different bucket. Option C is wrong because reading the bucket name from a text file stored in the same bucket creates a circular dependency: the function needs the bucket name to access the bucket, but it must first read the file from the bucket to get the name, which is impossible without prior knowledge of the bucket. Option D is wrong because using a KMS key to encrypt the bucket name and decrypt it in the function adds unnecessary complexity and overhead; environment variables are already encrypted at rest by default, and the bucket name is not sensitive data that requires custom encryption—this approach does not solve the configuration problem.

202
MCQmedium

A company has a legacy application that generates log files on an EC2 instance. The developer needs to stream these log files to Amazon CloudWatch Logs in real time. The developer installed the CloudWatch agent on the EC2 instance and configured it to monitor the log files. However, the logs are not appearing in CloudWatch Logs. The developer checks the agent status and sees that the agent is running. What is the most likely cause of this issue?

A.The log file format is not compatible with the CloudWatch agent.
B.The EC2 instance is in a private subnet without internet access.
C.The EC2 instance does not have an IAM role with the necessary CloudWatch Logs permissions.
D.The CloudWatch agent configuration file does not specify an existing log group.
AnswerC

For the CloudWatch agent to successfully publish log data, the EC2 instance profile must be associated with an IAM role that grants specific permissions to CloudWatch Logs. Essential permissions include logs:PutLogEvents to send log data, logs:CreateLogStream to create new log streams, and logs:DescribeLogStreams to check existing streams. Without these explicit permissions, the agent will be unauthorized to interact with the CloudWatch Logs service, leading to log ingestion failures.

Why this answer

The CloudWatch agent uses the EC2 instance's IAM role credentials to call the CloudWatch Logs API (logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents). If the instance profile lacks these permissions, the agent process runs but every API call is rejected with AccessDenied, so logs never appear. This is the most common cause when the agent status shows running but no data arrives.

Exam trap

DVA-C02 often tests the assumption that a 'running' agent means it is functioning — candidates overlook that the agent can run while lacking IAM permissions, and they pick network or configuration answers instead of checking the instance role's CloudWatch Logs policy.

How to eliminate wrong answers

Option A is wrong because the CloudWatch agent handles plain text, JSON, and many common log formats; format incompatibility would typically produce parsing warnings, not total absence of logs. Option B is wrong because an instance in a private subnet can still reach CloudWatch Logs through a VPC endpoint (interface endpoint for logs) or NAT gateway; lack of internet access alone is not the most likely cause and is easily remedied. Option D is wrong because the agent auto-creates the log group if it does not exist (given permissions), so a missing log group definition is not the typical failure mode.

203
MCQeasy

A developer is building a RESTful API using AWS Lambda and Amazon API Gateway. The API needs to support HTTP methods GET, POST, and DELETE. The developer wants to minimize code and operational overhead. Which API Gateway integration type should the developer use?

A.Lambda proxy integration
B.Lambda custom integration
C.HTTP integration
D.Mock integration
AnswerA

Lambda proxy integration is the recommended and most straightforward method for integrating API Gateway with AWS Lambda functions. It passes the entire incoming request, including headers, query parameters, path parameters, and body, directly to the Lambda function as a single JSON object. This simplifies the Lambda function's code, as it receives the raw request and is responsible for formatting the response in a specific API Gateway-compatible JSON structure, minimizing configuration overhead in API Gateway itself.

Why this answer

Lambda proxy integration is correct because API Gateway passes the entire HTTP request (method, path, headers, query string, body) directly to the Lambda function as a structured event, and the function returns a formatted response object. This eliminates the need to write mapping templates or configure method/request/response transformations, minimizing both code and operational overhead. It natively supports GET, POST, DELETE, and any other HTTP method without per-method configuration.

Exam trap

DVA-C02 often tests the difference between proxy and custom integrations, and candidates mistakenly choose custom integration thinking it reduces code, when in fact proxy integration is the one that minimizes code by avoiding mapping templates.

How to eliminate wrong answers

Option B is wrong because Lambda custom integration requires the developer to write mapping templates for request and response payloads, adding code and configuration overhead. Option C is wrong because HTTP integration is used to route requests to an existing HTTP endpoint (e.g., an on-premises or external API), not to a Lambda function. Option D is wrong because mock integration returns a static response without invoking any backend, so it cannot serve a functional RESTful API.

204
MCQmedium

A Lambda function needs temporary scratch space larger than the default while processing images. Which setting should be adjusted?

A.Reserved concurrency
B.Ephemeral storage size for /tmp
C.Function URL auth type
D.Dead-letter queue target
AnswerB

The ephemeral storage size for the "/tmp" directory directly controls the amount of local, temporary disk space available to a Lambda function during its execution. By increasing this configurable setting, a function can access more scratch space than the default 512 MB, which is essential for processing larger files or datasets locally. This directly fulfills the requirement for a larger temporary scratch space within the Lambda execution environment.

Why this answer

Lambda functions have a default /tmp storage of 512 MB, which is insufficient for large image processing tasks. Adjusting the ephemeral storage size (up to 10,240 MB) provides the necessary scratch space for temporary files, such as intermediate image buffers or resized outputs, without requiring external storage like EFS.

Exam trap

The trap here is that candidates confuse ephemeral storage with memory allocation or external storage services, assuming that increasing the function's memory or using S3 will solve the scratch space issue, when the /tmp directory is the only directly configurable scratch space within the Lambda execution environment.

How to eliminate wrong answers

Option A is wrong because reserved concurrency controls the maximum number of concurrent executions for a function, not storage capacity. Option C is wrong because the function URL auth type (e.g., AWS_IAM or NONE) determines authentication for HTTP invocations, not storage. Option D is wrong because a dead-letter queue target (e.g., SQS or SNS) is used for capturing failed asynchronous invocations, not for providing scratch space.

205
MCQhard

A company runs a microservices architecture on Amazon ECS with Fargate. Each service exposes an HTTP API and needs to be accessible only from the company's internal network via a VPN. The services are deployed in private subnets. What is the MOST secure and scalable way to expose these services?

A.Create a VPC Endpoint service powered by PrivateLink and a Network Load Balancer in front of the services.
B.Place an Application Load Balancer in public subnets and point to the services' target groups.
C.Use a NAT Gateway to allow inbound traffic from the VPN to the services.
D.Use an Internet Gateway and route traffic from the VPN to the services.
AnswerA

A VPC Endpoint service, powered by AWS PrivateLink, enables secure, private connectivity from other VPCs or on-premises networks (via VPN/Direct Connect) to services hosted within your VPC. By placing a Network Load Balancer (NLB) in front of the ECS services, the PrivateLink endpoint can expose these services securely. This setup ensures traffic remains entirely within the AWS network and your private network, bypassing the public internet and maintaining strict security for internal-only access.

Why this answer

AWS PrivateLink with a VPC Endpoint service and a Network Load Balancer (NLB) allows you to expose services running in private subnets to other VPCs or on-premises networks via VPN without traversing the public internet. The NLB handles TCP traffic at Layer 4, and the VPC Endpoint service provides secure, scalable connectivity by creating elastic network interfaces in the consumer VPC, ensuring traffic stays within the AWS network. This approach is both secure (no public exposure) and scalable (NLB handles high throughput and availability).

Exam trap

The trap here is that candidates often confuse NAT Gateway (outbound only) with a solution for inbound traffic, or they assume an ALB in public subnets is acceptable because it can be restricted via security groups, but that still exposes the services to the internet at the network layer.

How to eliminate wrong answers

Option B is wrong because placing an Application Load Balancer in public subnets would expose the services to the internet, violating the requirement that services be accessible only from the internal network via VPN. Option C is wrong because a NAT Gateway is used for outbound traffic from private subnets to the internet, not for inbound traffic from a VPN; it cannot accept inbound connections initiated from outside the VPC. Option D is wrong because an Internet Gateway is designed for direct internet access, and routing VPN traffic through it would expose services to the public internet, defeating the purpose of private subnets and internal-only access.

206
MCQeasy

A developer needs to deploy a containerized application on AWS. The application requires persistent storage for stateful data. Which AWS compute service should the developer choose?

A.Amazon ECS with Fargate
B.AWS Elastic Beanstalk
C.Amazon EKS with Fargate
D.AWS Lambda
AnswerA

This combination is ideal for deploying containerized applications requiring persistent storage because Amazon ECS provides robust container orchestration, while Fargate eliminates the need to manage underlying EC2 instances. For stateful applications, ECS tasks running on Fargate can seamlessly integrate with Amazon EFS for shared file system access or utilize bind mounts to local ephemeral storage (though EFS is preferred for true persistence across task restarts). This offers a fully managed, scalable, and highly available solution for stateful container workloads without server management overhead.

Why this answer

Amazon ECS with Fargate is the best choice for deploying a containerized application with persistent storage. Fargate supports persistent storage by integrating with Amazon EFS. While Amazon EKS with Fargate also supports persistent storage, ECS with Fargate offers simpler management and is often preferred for stateful containers.

AWS Elastic Beanstalk can run containers but is more opinionated and less flexible for stateful configurations. AWS Lambda is stateless and ephemeral, not suitable for persistent storage.

207
MCQmedium

A company is building a serverless application using AWS Lambda to process user uploads to Amazon S3. The Lambda function needs to access a DynamoDB table to store metadata. What is the MOST secure way to grant the Lambda function access to DynamoDB?

A.Store IAM user access keys in the Lambda function's environment variables.
B.Use a resource-based policy on the DynamoDB table to allow the Lambda function's ARN.
C.Create an IAM role with a policy that grants DynamoDB access and attach it to the Lambda function.
D.Hardcode the DynamoDB credentials in the Lambda function code.
AnswerC

An IAM role attached to the Lambda function supplies temporary credentials via the execution environment, so no long-term keys are stored in code or environment variables. This satisfies least-privilege access to DynamoDB without embedding static credentials.

Why this answer

AWS Lambda uses an IAM role (execution role) to obtain temporary credentials via the AWS Security Token Service (STS). Attaching a policy that grants DynamoDB access to this role follows the principle of least privilege and avoids long-term credentials. This is the standard, secure pattern for granting Lambda functions access to other AWS services.

Exam trap

The trap here is that candidates confuse resource-based policies (which work for services like S3 and SQS) with the need for an execution role for Lambda, leading them to incorrectly select Option B, even though DynamoDB does not support resource-based policies for granting access to Lambda functions.

How to eliminate wrong answers

Option A is wrong because storing IAM user access keys in environment variables introduces long-term credentials that can be leaked, and it violates the AWS best practice of using temporary credentials via IAM roles. Option B is wrong because resource-based policies on DynamoDB tables cannot grant access to a Lambda function directly; DynamoDB does not support resource-based policies for Lambda invocation, and the Lambda function still needs an execution role to assume permissions. Option D is wrong because hardcoding credentials in code is insecure, makes rotation difficult, and violates the principle of never embedding secrets in application code.

208
MCQeasy

A developer needs to send large files (up to 5 GB) from a web application to Amazon S3. The application runs on EC2 instances. Which approach is MOST efficient and reliable?

A.Save the file to EC2 instance store and then copy to S3.
B.Upload the file as a single S3 PutObject operation.
C.Use S3 multipart upload to upload the file in parts.
D.Use S3 Transfer Acceleration to upload the file.
AnswerC

S3 multipart upload is the recommended and most efficient method for uploading large objects, especially those exceeding 100 MB, and is required for objects larger than 5 GB. This method breaks the file into smaller, independent parts, which can be uploaded concurrently, significantly improving throughput and resilience. If a part fails, only that specific part needs to be re-uploaded, rather than the entire file, ensuring greater reliability and faster recovery from network issues.

Why this answer

S3 multipart upload is the most efficient and reliable approach for uploading large files (up to 5 GB) because it allows the file to be split into smaller parts that can be uploaded in parallel, improving throughput and resilience. If a part fails, only that part needs to be retried, not the entire file, and the upload can be paused and resumed. This is the recommended AWS method for objects larger than 100 MB and is required for objects over 5 GB.

Exam trap

The trap here is that candidates may think S3 Transfer Acceleration (Option D) is the best choice for large files because it speeds up transfers, but they overlook that multipart upload is the fundamental mechanism for reliability and efficiency with large objects, while Transfer Acceleration is an optional performance enhancement that can be used on top of multipart upload.

How to eliminate wrong answers

Option A is wrong because saving to EC2 instance store is ephemeral (data is lost on instance stop/termination) and adds an unnecessary intermediate step with no benefit for reliability or efficiency. Option B is wrong because a single PutObject operation for a 5 GB file is prone to network interruptions, requires the entire upload to restart on failure, and has a hard limit of 5 GB (the maximum object size in a single PUT is 5 GB, but multipart is still recommended for files over 100 MB). Option D is wrong because S3 Transfer Acceleration optimizes network path and speed for long-distance transfers but does not provide the reliability benefits of parallel uploads or retry granularity; it can be combined with multipart upload but is not the primary solution for reliability.

209
MCQmedium

A developer is building a serverless application using AWS SAM. The application includes a Lambda function that needs read-only access to an S3 bucket. The developer wants to use SAM's built-in policy templates to grant this permission. Which policy template should be used in the SAM template?

A.S3ReadPolicy
B.S3CrudPolicy
C.S3FullAccessPolicy
D.S3StreamPolicy
AnswerA

The S3ReadPolicy template grants a Lambda function the necessary `s3:GetObject` permission to retrieve specific objects and `s3:ListBucket` to enumerate the contents of a designated S3 bucket. This adheres strictly to the principle of least privilege, ensuring the application can only perform read operations without any ability to modify or delete data. It is the most appropriate choice for scenarios requiring only data retrieval from S3.

Why this answer

The S3ReadPolicy template is the correct choice because it grants read-only access to an S3 bucket, which aligns with the requirement for the Lambda function. AWS SAM provides this built-in IAM policy template to simplify attaching least-privilege permissions, specifically allowing s3:GetObject, s3:ListBucket, and similar read operations.

Exam trap

The trap here is that candidates may confuse S3CrudPolicy with read-only access, but CRUD implies full data manipulation (create, read, update, delete), which is more permissive than the required read-only scope.

How to eliminate wrong answers

Option B (S3CrudPolicy) is wrong because it grants create, read, update, and delete permissions, which exceeds the required read-only access and violates the principle of least privilege. Option C (S3FullAccessPolicy) is wrong because it provides full administrative access to the S3 bucket, including delete and write operations, far beyond the read-only requirement. Option D (S3StreamPolicy) is wrong because it is not a valid SAM policy template; SAM does not include a template named S3StreamPolicy, and streaming permissions are typically associated with services like Kinesis or DynamoDB Streams, not S3.

210
Multi-Selectmedium

A developer is troubleshooting a Lambda function that times out when processing large files from Amazon S3. The function is configured with a 3-minute timeout and 128 MB memory. Which TWO actions would MOST likely resolve the issue? (Choose TWO.)

Select 2 answers
A.Use S3 multipart upload for large files to improve throughput.
B.Increase the memory allocation for the Lambda function.
C.Change the S3 event notification to send messages to an Amazon SQS queue instead.
D.Update the Lambda function code to use a more efficient algorithm.
E.Increase the Lambda function timeout to 15 minutes.
AnswersB, E

In AWS Lambda, memory allocation is directly correlated with the CPU power and network bandwidth provisioned for the function's execution environment. For processing large files, increasing memory provides more RAM for data buffering and in-memory operations, while the increased CPU and network throughput accelerate data retrieval from S3 and subsequent computational tasks. This combined performance boost can significantly reduce the overall execution time, helping the function complete within its timeout.

Why this answer

Increasing the memory allocation for a Lambda function also increases CPU and network bandwidth, which can significantly speed up the processing of large files, helping the function complete within the timeout. Option E is correct because increasing the Lambda function timeout directly addresses the timeout issue, giving the function more time to complete processing large files. Option A is incorrect because S3 multipart upload is used for uploading large objects to S3, not for downloading/reading from S3; it does not improve data ingestion into a Lambda function.

Option C is incorrect because sending events to SQS does not affect the processing speed of a single large file; it only decouples the event source. Option D is too generic; while a more efficient algorithm could help, it is not a guaranteed or most likely fix compared to increasing memory or timeout.

Exam trap

The trap is that candidates may incorrectly assume S3 multipart upload speeds up reading from S3, when it is only for uploading. A common mistake is to overlook increasing timeout as a valid fix, but in the AWS Developer Associate exam, both memory increase and timeout increase are standard solutions for Lambda timeouts.

211
MCQeasy

A developer is writing a Lambda function that processes records from a Kinesis stream. The function must handle duplicate records and ensure exactly-once processing. Which approach should the developer use?

A.Disable retries in the Lambda function to avoid processing duplicates.
B.Enable record ordering in the Kinesis stream.
C.Use a unique identifier for each record and store processed IDs in a DynamoDB table to skip duplicates.
D.Send the records to an SQS FIFO queue for deduplication.
AnswerC

This is the most effective and recommended approach for ensuring idempotent processing of Kinesis records by a Lambda function. By assigning a unique identifier (e.g., a UUID or a combination of source ID and timestamp) to each record and storing these IDs in a DynamoDB table upon successful processing, the Lambda function can check if a record has already been processed before executing its core logic. This prevents duplicate processing even with Kinesis's "at-least-once" delivery semantics and Lambda retries, ensuring data consistency.

Why this answer

Exactly-once processing in a Kinesis-triggered Lambda function requires idempotency. By using a unique identifier (e.g., Kinesis sequence number or a business key) and storing processed IDs in a DynamoDB table, the function can check for duplicates before processing each record. This pattern ensures that even if Kinesis delivers the same record multiple times (due to retries or shard rebalancing), the record is only processed once.

Exam trap

The trap here is that candidates confuse ordering with deduplication, assuming that enabling record ordering (Option B) prevents duplicates, when in fact ordering only ensures records are processed in sequence, not that each record is processed only once.

How to eliminate wrong answers

Option A is wrong because disabling retries does not prevent duplicates; Kinesis can still deliver the same record multiple times due to its at-least-once delivery guarantee, and disabling retries would cause data loss on transient failures. Option B is wrong because record ordering (enabled by default in Kinesis streams) controls the sequence of records within a shard but does not eliminate duplicate records; duplicates can still occur from producer retries or consumer rebalancing. Option D is wrong because sending records to an SQS FIFO queue does not deduplicate records already delivered by Kinesis; the deduplication ID in SQS FIFO only prevents duplicates within the queue itself, and the Lambda function would still need to handle duplicates from the Kinesis source.

212
MCQeasy

A developer creates an AWS CloudFormation stack with the template snippet shown. The stack creation fails with the error: "Bucket with name my-unique-bucket-12345 already exists." What is the MOST likely cause?

A.The developer does not have permission to create S3 buckets.
B.The bucket name is already taken by another AWS account.
C.The CloudFormation template has a syntax error.
D.The bucket name was used by another stack in the same account.
AnswerB

S3 bucket names are globally unique across all AWS accounts and regions. This means that if another AWS account has already registered the desired bucket name, any attempt to create a new bucket with that exact name, even in a different account or region, will result in a `BucketAlreadyExists` error. This fundamental constraint ensures a unique namespace for all S3 resources worldwide.

Why this answer

The error message 'Bucket with name my-unique-bucket-12345 already exists' indicates that the bucket name is globally unique across all AWS accounts. Since the bucket name is already taken, the most likely cause is that another AWS account has already created a bucket with that exact name. S3 bucket names are unique across all of AWS, not just within a single account or region.

Exam trap

The trap here is that candidates may assume bucket names only need to be unique within their own account or region, but AWS S3 enforces global uniqueness across all accounts and regions, making Option D a plausible but incorrect choice.

How to eliminate wrong answers

Option A is wrong because if the developer lacked permissions to create S3 buckets, the error would be an authorization failure (e.g., 'Access Denied'), not a 'bucket already exists' error. Option C is wrong because a syntax error in the CloudFormation template would produce a validation error (e.g., 'Template format error') before any resource creation attempt. Option D is wrong because if the bucket name was used by another stack in the same account, the error would still be 'already exists', but the question asks for the MOST likely cause; since bucket names are globally unique, the name being taken by any account (including another account) is the primary reason, and the error message does not specify it was from the same account.

213
MCQmedium

A developer is deploying a Node.js application on AWS Elastic Beanstalk. The application uses environment variables for database credentials. The developer wants to ensure that the credentials are encrypted at rest and rotated automatically. Which solution meets these requirements with minimal effort?

A.Store the credentials in AWS Secrets Manager and retrieve them in the application code. Configure automatic rotation.
B.Hardcode the credentials in the application code and use environment variables for different environments.
C.Store the credentials in AWS Systems Manager Parameter Store as SecureString parameters and reference them in the application code.
D.Use Elastic Beanstalk environment properties to set the credentials as plaintext environment variables.
AnswerA

AWS Secrets Manager is the most secure and recommended service for storing sensitive credentials. It encrypts secrets at rest and in transit using AWS Key Management Service (KMS), and critically, it supports automatic rotation of credentials for various database types and other services. This significantly reduces the risk of long-lived, compromised credentials and simplifies credential lifecycle management, aligning with security best practices for a Node.js application on Elastic Beanstalk.

Why this answer

AWS Secrets Manager is the correct choice because it provides built-in automatic rotation of secrets (including database credentials) with minimal configuration, and it encrypts secrets at rest using AWS KMS. The developer can retrieve the credentials at runtime via the AWS SDK, avoiding hardcoding or plaintext exposure. Elastic Beanstalk environment properties do not offer encryption at rest or rotation, and while Parameter Store SecureString parameters encrypt at rest, they lack native automatic rotation without additional custom logic.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store SecureString parameters with Secrets Manager, overlooking that Parameter Store lacks native automatic rotation, which is explicitly required by the question.

How to eliminate wrong answers

Option B is wrong because hardcoding credentials in application code violates security best practices, does not encrypt credentials at rest, and requires manual rotation. Option C is wrong because AWS Systems Manager Parameter Store SecureString parameters encrypt at rest but do not support automatic rotation natively; rotation would require a custom AWS Lambda function or manual intervention. Option D is wrong because Elastic Beanstalk environment properties store credentials as plaintext environment variables, which are not encrypted at rest and cannot be rotated automatically.

214
MCQmedium

A company is using AWS Lambda with a 1 GB memory configuration. The function processes large CSV files from S3 and occasionally times out after 15 seconds. The function currently uses synchronous invocation. What is the MOST cost-effective solution to handle larger files without losing data?

A.Increase the Lambda timeout to 15 minutes and keep memory at 1 GB.
B.Switch to asynchronous Lambda invocation to allow up to 15 minutes of processing.
C.Increase the Lambda memory to 3 GB to improve processing speed.
D.Use AWS Step Functions to orchestrate the processing in smaller chunks.
AnswerA

Increasing the Lambda timeout to its maximum of 15 minutes directly addresses the problem if the function simply requires more execution time to complete its task. This is often the most cost-effective solution for tasks that are not CPU-bound but rather time-consuming due to sequential operations or external dependencies, as it avoids increasing compute resources unnecessarily. Keeping memory at 1 GB ensures that billing remains efficient by only paying for the additional execution duration, not for unused processing power.

Why this answer

Increasing the Lambda timeout from 15 seconds to 15 minutes directly addresses the timeout issue without incurring additional costs. Keeping memory at 1 GB avoids the higher per-GB-second cost of larger memory configurations, making it the most cost-effective solution. Lambda charges based on memory allocation and execution duration, so extending the timeout alone does not increase the cost per invocation if the function runs for the same duration.

Exam trap

The trap here is that candidates assume asynchronous invocation has a longer timeout than synchronous, but both share the same 15-minute maximum; the real differentiator is that asynchronous invocation allows retries and queueing, not extended execution time.

How to eliminate wrong answers

Option B is wrong because switching to asynchronous invocation does not change the maximum execution duration; Lambda's synchronous and asynchronous invocations both have a maximum timeout of 15 minutes (900 seconds), so the function would still time out after 15 seconds unless the timeout is increased. Option C is wrong because increasing memory to 3 GB would increase processing speed but also triples the cost per GB-second, making it less cost-effective than simply extending the timeout at 1 GB. Option D is wrong because using AWS Step Functions to orchestrate processing in smaller chunks adds complexity and cost (per state transition) without addressing the root cause—the function's timeout limit—and may still require increasing the Lambda timeout for each chunk.

215
Multi-Selecteasy

Which TWO AWS services can be used to store and retrieve application configuration data? (Choose two.)

Select 2 answers
A.AWS AppConfig
B.AWS Systems Manager Parameter Store
C.AWS Secrets Manager
D.Amazon S3
E.AWS CloudFormation
AnswersA, B

AWS AppConfig is a managed service specifically designed for creating, managing, and deploying application configurations. It enables developers to quickly and safely roll out configuration changes to applications hosted on EC2 instances, containers, or Lambda functions. AppConfig provides features like validation, monitoring, and controlled deployment strategies, including phased rollouts and rollbacks, ensuring reliable and safe updates to application settings.

Why this answer

AWS AppConfig is a feature of AWS Systems Manager that allows you to create, manage, and deploy application configuration data separately from your code. It supports feature flags, tuning parameters, and other dynamic configuration, and can validate configuration changes before deployment to reduce risk. This makes it a correct choice for storing and retrieving application configuration data.

Exam trap

The trap here is that candidates often confuse AWS Secrets Manager with Systems Manager Parameter Store, but Secrets Manager is specifically for secrets (not general config) and has a per-secret cost, while Parameter Store (a correct answer) is designed for configuration data and offers a free tier.

216
MCQmedium

A company has an AWS Lambda function that processes messages from an Amazon SQS queue. The function sometimes fails due to transient errors. The developer wants to ensure that failed messages are retried automatically and then sent to a dead-letter queue after three failed attempts. How should the developer configure this?

A.Enable Lambda function's DLQ and set the retry attempts to 3.
B.Configure the Lambda function's reserved concurrency to 0 and set the DLQ on the function.
C.Configure the SQS queue with a redrive policy and a dead-letter queue. Set the maxReceiveCount to 3.
D.Use an Amazon SNS topic to send failed messages to a DLQ after three Lambda invocations.
AnswerC

This is the correct approach for handling message failures when an SQS queue triggers a Lambda function. By configuring a redrive policy on the SQS queue itself, along with a dead-letter queue and a `maxReceiveCount` of 3, SQS will automatically manage message retries. If the Lambda function fails to process a message three times, SQS will move that message to the specified dead-letter queue for later inspection and reprocessing, ensuring no messages are lost indefinitely.

Why this answer

Amazon SQS supports a redrive policy that automatically moves messages to a dead-letter queue (DLQ) after a specified number of receive attempts. By setting maxReceiveCount to 3, the SQS queue will retry delivering the message to the Lambda function up to three times (including the initial attempt). After three failed processing attempts, the message is automatically sent to the configured DLQ.

This approach decouples retry logic from the Lambda function itself and leverages SQS's built-in reliability features.

Exam trap

The trap here is that candidates often confuse Lambda's asynchronous invocation DLQ (for events like S3 or SNS) with the SQS redrive policy, mistakenly thinking they can configure retries and DLQ on the Lambda function itself rather than on the SQS queue.

How to eliminate wrong answers

Option A is wrong because Lambda functions do not have a configurable retry count for SQS-triggered invocations; Lambda's built-in DLQ is for asynchronous invocations (e.g., from S3 or SNS), not for SQS event source mappings, and setting retry attempts on the function itself is not supported. Option B is wrong because setting reserved concurrency to 0 would prevent the Lambda function from executing at all, causing all messages to fail immediately, and the DLQ on the function is again irrelevant for SQS-triggered invocations. Option D is wrong because SNS topics are not used to retry or manage DLQ behavior for SQS-triggered Lambda functions; the retry and DLQ logic must be configured on the SQS queue itself, not via an SNS topic.

217
Multi-Selecthard

A developer is building an API using Amazon API Gateway and AWS Lambda. The API must authenticate users using a third-party OAuth 2.0 provider. Which TWO components are required to implement this authentication?

Select 2 answers
A.The OAuth 2.0 access token in the Authorization header
B.Amazon CloudFront distribution for API caching
C.An API Gateway resource policy that invokes the Lambda authorizer
D.An AWS Lambda authorizer function
E.An Amazon Cognito user pool as the OAuth provider
AnswersA, D

Passing the third-party OAuth 2.0 access token in the Authorization header lets API Gateway validate it against the provider's JWKS endpoint via a Lambda authoriser or JWT authoriser, satisfying the requirement to authenticate users through an external OAuth 2.0 provider rather than native AWS credentials.

Why this answer

Option D is correct because a Lambda authorizer (formerly a custom authorizer) is the API Gateway mechanism that lets you plug in custom authentication logic; the function receives the caller's token, validates it against the third-party OAuth 2.0 provider (e.g., by verifying the JWT signature or calling the provider's introspection endpoint), and returns an IAM policy that allows or denies the request. Option A is correct because the client must present the OAuth 2.0 access token to API Gateway, and the standard convention is to send it in the Authorization header (typically as 'Bearer <token>'), which is exactly what the Lambda authorizer reads to perform validation. Option B is not required because a CloudFront distribution is only an optional caching/edge layer and plays no role in OAuth 2.0 authentication.

Option C is incorrect because resource policies control access to the API based on source IP, VPC endpoint, or AWS account/IAM principal, not by invoking a Lambda authorizer; the authorizer is attached via the API method's authorization settings. Option E is incorrect because the scenario specifies a third-party OAuth 2.0 provider, so an Amazon Cognito user pool is not needed and would instead make Cognito the identity provider.

Exam trap

The trap is that candidates may think a resource policy is needed to invoke the Lambda authorizer, but the authorizer is configured separately via API Gateway's authorizer settings. The correct required components are the OAuth token and a Lambda authorizer function.

218
MCQeasy

A developer is building a REST API using Amazon API Gateway and AWS Lambda. The API needs to support a custom domain name and an SSL/TLS certificate. Which AWS service should the developer use to manage the SSL/TLS certificate?

A.AWS Key Management Service (AWS KMS)
B.AWS Certificate Manager (ACM)
C.AWS Identity and Access Management (IAM)
D.AWS Secrets Manager
AnswerB

AWS Certificate Manager (ACM) is the dedicated service for provisioning, managing, and deploying SSL/TLS certificates for use with AWS services. It allows you to easily request public or private certificates, which are then automatically renewed and deployed to integrated services like API Gateway, CloudFront, and Elastic Load Balancers. This seamless integration and automated lifecycle management make ACM the correct and preferred choice for securing custom domains on API Gateway.

Why this answer

AWS Certificate Manager (ACM) is the correct service for provisioning, managing, and deploying SSL/TLS certificates for use with AWS services like API Gateway. ACM integrates directly with API Gateway to automatically renew certificates and attach them to custom domain names, ensuring secure HTTPS connections without manual intervention.

Exam trap

The trap here is that candidates confuse AWS KMS or Secrets Manager with certificate management, but ACM is the only service that directly provisions and manages SSL/TLS certificates for use with AWS services like API Gateway and CloudFront.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a service for creating and controlling encryption keys used to encrypt data at rest, not for managing SSL/TLS certificates. Option C is wrong because IAM is used for managing user identities and permissions, not for issuing or managing SSL/TLS certificates. Option D is wrong because AWS Secrets Manager is designed to securely store and rotate secrets like database credentials or API keys, not for managing SSL/TLS certificates.

219
MCQmedium

A company is using AWS Lambda to process messages from an Amazon SQS queue. The Lambda function sometimes fails to process a message due to a transient error. The company wants to automatically retry failed messages up to 3 times, with a 5-minute delay between retries. What should the company configure?

A.Configure a dead-letter queue on the Lambda function with a redrive policy that allows up to 3 retries and a 5-minute delay.
B.Use AWS Step Functions to poll the SQS queue and implement a retry loop with exponential backoff.
C.Set the Lambda function's reserved concurrency to 1 and enable the 'Retry attempts' option to 3 in the function configuration.
D.Configure the SQS queue with a delivery delay of 5 minutes and a redrive policy to move messages to a dead-letter queue after 3 receives.
AnswerD

Correct. Configuring the SQS queue with a redrive policy (maxReceiveCount = 3) moves messages to a dead-letter queue after 3 receives. The delay between retries is achieved by setting the visibility timeout to 5 minutes. The phrase 'delivery delay' in the option is not exactly correct, but it is the best choice.

Why this answer

For an SQS-triggered Lambda, retries are managed by SQS. To retry a failed message up to 3 times with a 5-minute delay between attempts, set the queue's visibility timeout to 5 minutes and configure a redrive policy with maxReceiveCount = 3 so the message is moved to a dead-letter queue after 3 failed receives. Note that a delivery delay only postpones the initial delivery of a message and does not create a delay between retries, so option D's 'delivery delay' is the wrong mechanism.

Option A is incorrect because Lambda functions do not have a redrive policy; retries for SQS-triggered Lambda are managed by SQS. Option B is unnecessary overhead. Option C is invalid because reserved concurrency and a 'Retry attempts' setting do not control SQS-triggered Lambda retries.

Exam trap

Candidates may think that the Lambda function's DLQ configuration controls retries, but in reality, for SQS-triggered Lambda, retries are managed by SQS's visibility timeout and redrive policy. The visibility timeout acts as the delay between retries.

How to eliminate wrong answers

Option B is wrong because AWS Step Functions is an orchestration service, not a retry mechanism for Lambda-SQS integration; using it would add unnecessary complexity and cost, and it does not directly control SQS retry delays. Option C is wrong because Lambda's reserved concurrency controls the number of concurrent executions, not retry attempts; there is no 'Retry attempts' option in Lambda function configuration for SQS-triggered invocations. Option D is wrong because configuring a delivery delay of 5 minutes on the SQS queue delays all messages initially, not between retries; the redrive policy on the queue moves messages to a DLQ after a specified number of receives, but Lambda's retry behavior is managed by the function's DLQ configuration, not the queue's.

220
MCQmedium

A company is using Amazon CloudFront to serve content from an Application Load Balancer (ALB) origin. The ALB is configured as an internal load balancer in a VPC. Users are getting HTTP 502 errors when accessing the CloudFront distribution. What is the MOST likely cause?

A.The ALB has AWS WAF enabled, blocking CloudFront IP addresses.
B.The CloudFront distribution's cache behavior is set to cache all objects.
C.The ALB is not internet-facing, so CloudFront cannot reach it.
D.The CloudFront distribution is not associated with a VPN connection to the VPC.
AnswerC

CloudFront edge locations operate on the public internet and require public network connectivity to reach their configured origins. An Application Load Balancer (ALB) configured as 'internal' is only accessible via private IP addresses within its Virtual Private Cloud (VPC) and is not exposed to the public internet. Consequently, CloudFront would be unable to establish a network connection to an internal ALB, resulting in a 502 Bad Gateway error as it cannot retrieve content from the unreachable origin.

Why this answer

The ALB is configured as an internal load balancer, meaning it only has private IP addresses and is accessible only within the VPC. CloudFront, being an AWS edge service outside the VPC, cannot route traffic to a private IP address without additional configuration such as a VPC origin or a public-facing ALB. This results in HTTP 502 errors because CloudFront cannot establish a connection to the origin.

Exam trap

The trap here is that candidates may assume CloudFront can reach any AWS resource within the same account, but they overlook that internal load balancers are not publicly accessible, and CloudFront requires a publicly routable endpoint or a VPC origin configuration.

How to eliminate wrong answers

Option A is wrong because AWS WAF on an ALB blocks or allows traffic based on rules, but it does not prevent CloudFront from reaching the ALB if the ALB is internet-facing; the core issue here is network reachability, not WAF filtering. Option B is wrong because caching all objects in CloudFront does not cause 502 errors; caching affects how content is served to users, not the origin connectivity itself. Option D is wrong because CloudFront does not require a VPN connection to reach an origin; it uses public internet or AWS PrivateLink/VPC origins, but a VPN is not a standard requirement for CloudFront-to-ALB communication.

221
MCQhard

A company runs a critical application on AWS Lambda that processes real-time financial transactions. The Lambda function is triggered by an SQS queue that receives messages from an API Gateway. Recently, the team has observed an increase in processing errors and occasional data loss. Upon investigation, they find that the Lambda function's concurrency limit is set to 5, and the SQS queue has a visibility timeout of 30 seconds. The function typically takes 2 seconds to process a message, but during peak hours, the queue depth grows to thousands of messages. The errors occur when the Lambda function throws an exception, causing the message to return to the queue after the visibility timeout expires. However, some messages are never processed again and are eventually lost. The team suspects that the messages are being sent to the dead-letter queue (DLQ) after multiple retries, but the DLQ is not configured. The team needs to ensure that no messages are lost and that processing errors are handled appropriately. What should the team do to resolve this issue?

A.Increase the Lambda concurrency limit to 100 and set the SQS visibility timeout to 60 seconds.
B.Configure an Amazon CloudWatch alarm on the queue depth and set a Lambda function as the on-failure destination for asynchronous invocations.
C.Change the Lambda invocation mode to synchronous and use API Gateway as a proxy to invoke the function directly.
D.Configure a dead-letter queue on the SQS source queue and set the maximum receives to 3. Implement error handling in the Lambda function to catch exceptions and log them.
AnswerD

Configuring a dead-letter queue (DLQ) directly on the SQS source queue is the most effective solution for preventing message loss from persistently failing Lambda invocations. By setting the `maximum receives` attribute to 3, any message that fails to be processed successfully after three attempts will automatically be moved to the specified DLQ. This preserves the message for later inspection, manual reprocessing, or automated re-ingestion, while robust error handling within the Lambda function ensures that exceptions are gracefully caught and logged for debugging purposes.

Why this answer

Messages are lost because the SQS source queue has no dead-letter queue and the Lambda function has no error handling, so after repeated failed receives messages are discarded or expire. Configuring a DLQ on the source queue with a maximumReceiveCount of 3 preserves failed messages, and adding try/catch error handling in the function ensures exceptions are logged and handled rather than silently failing. This directly addresses both the data loss and the error-handling requirement.

Exam trap

DVA-C02 often tests the confusion between Lambda asynchronous invocation destinations (for SNS/EventBridge/S3 triggers) and SQS event source mapping, leading candidates to pick on-failure destinations that do not apply to poll-based SQS triggers.

How to eliminate wrong answers

Option A is wrong because raising concurrency and visibility timeout improves throughput and reduces duplicate processing but does not prevent message loss when the function throws exceptions and no DLQ exists. Option B is wrong because Lambda on-failure destinations apply to asynchronous invocations, whereas SQS-triggered Lambda uses event source mapping (poll-based) and does not support on-failure destinations; a CloudWatch alarm on queue depth is monitoring, not a loss-prevention mechanism. Option C is wrong because switching to synchronous API Gateway invocation removes SQS buffering and decoupling, increases coupling and failure risk, and does not address the retry/DLQ requirement.

222
MCQeasy

A company is using AWS CodePipeline to automate the deployment of a web application. The pipeline has three stages: Source (Amazon S3), Build (AWS CodeBuild), and Deploy (AWS CodeDeploy). The application is deployed to an Auto Scaling group of EC2 instances. Recently, a deployment failed because the CodeDeploy agent on one of the instances was not running. The developer wants to ensure that the CodeDeploy agent is always running on all instances. What is the MOST efficient solution?

A.Use AWS CloudTrail to monitor the CodeDeploy agent status and trigger an AWS Lambda function to restart it.
B.Configure a CloudWatch alarm to detect when the CodeDeploy agent is not running and restart it automatically.
C.Modify the Auto Scaling group's launch configuration to include a user data script that installs and starts the CodeDeploy agent.
D.Use AWS Systems Manager Run Command to run a script that checks and restarts the CodeDeploy agent on a schedule.
AnswerC

Including a user data script in an Auto Scaling group's launch configuration or launch template is the most effective and proactive method. User data scripts execute automatically when an EC2 instance first launches, allowing for the installation and startup of necessary software, including the CodeDeploy agent. This ensures that every new instance provisioned by the Auto Scaling group is immediately ready to receive CodeDeploy deployments without manual intervention or reactive checks, making it a robust and scalable solution.

Why this answer

The correct option is C: modifying the Auto Scaling group's launch configuration to include a user data script that installs and starts the CodeDeploy agent. This is the most efficient solution because user data scripts run automatically on every new EC2 instance at launch, ensuring the CodeDeploy agent is installed and started on all instances without manual intervention or ongoing monitoring. It directly addresses the root cause by making agent installation part of the instance provisioning process.

Option A is inefficient because CloudTrail records API activity, not agent process status, and adding Lambda-based remediation is unnecessarily complex. Option B is not viable because CloudWatch cannot natively detect whether a local process like the CodeDeploy agent is running without custom metrics or agents. Option D could work but requires scheduled Run Command executions and doesn't guarantee the agent is present on newly launched instances before deployments occur.

223
MCQeasy

A developer is using AWS CodePipeline to automate the deployment of a web application. The developer wants to run unit tests after the source stage and before deploying to a staging environment. Which action should the developer add to the pipeline?

A.AWS CodeBuild
B.AWS CodeCommit
C.AWS CloudFormation
D.AWS CodeDeploy
AnswerA

AWS CodeBuild is a fully managed continuous integration service that compiles source code, runs tests, and produces deployable artifacts. Within an AWS CodePipeline, CodeBuild is typically configured as a build or test stage, executing unit tests, integration tests, or even security scans defined in a `buildspec.yml` file. This ensures that code quality and functionality are validated thoroughly before the application proceeds to subsequent deployment stages, making it the correct choice for automating the testing phase.

Why this answer

AWS CodeBuild is the correct service to run unit tests in a CodePipeline because it provides a fully managed build environment that can execute test commands defined in a buildspec file. By adding a CodeBuild action to the pipeline after the source stage, the developer can run unit tests and fail the pipeline if tests do not pass, ensuring only validated code proceeds to the staging deployment.

Exam trap

The trap here is that candidates may confuse CodeDeploy as the service for running tests because it handles deployments, but CodeDeploy does not execute build or test commands; it only deploys pre-built artifacts.

How to eliminate wrong answers

Option B (AWS CodeCommit) is wrong because it is a source control service for storing code, not a service for executing build or test commands. Option C (AWS CloudFormation) is wrong because it is an infrastructure-as-code service for provisioning AWS resources, not for running unit tests. Option D (AWS CodeDeploy) is wrong because it automates code deployment to compute services like EC2 or Lambda, but it does not execute unit tests; tests must be run before deployment.

224
MCQhard

An application running on Amazon EC2 instances in an Auto Scaling group processes messages from an SQS queue. The application runs in a private subnet and needs to send metrics to Amazon CloudWatch. How can the developer ensure the EC2 instances can send metrics without traversing the internet?

A.Attach a NAT Gateway to the private subnet and update the route table.
B.Install the CloudWatch agent on each instance and configure it to use a proxy.
C.Attach an Internet Gateway to the VPC and assign public IPs to instances.
D.Create a VPC Endpoint for CloudWatch (com.amazonaws.region.monitoring).
AnswerD

Creating a VPC Endpoint for CloudWatch, specifically an interface endpoint using the `com.amazonaws.region.monitoring` service name, establishes a private connection between your VPC and CloudWatch. This allows EC2 instances in private subnets to send metrics and logs to CloudWatch entirely within the AWS network, bypassing the public internet. This solution significantly enhances security and compliance by keeping all traffic private and eliminating internet egress for this communication.

Why this answer

A VPC Endpoint for CloudWatch (com.amazonaws.region.monitoring) allows EC2 instances in a private subnet to send metrics to CloudWatch over the AWS network without traversing the internet. This is achieved by creating an Interface Endpoint (powered by AWS PrivateLink) that provides private connectivity to CloudWatch using private IP addresses from your subnet, avoiding the need for an internet gateway, NAT gateway, or virtual private gateway.

Exam trap

Candidates often confuse VPC Endpoints with NAT Gateways or Internet Gateways, mistakenly thinking that any outbound traffic to AWS services requires internet access. Additionally, remember that CloudWatch uses an Interface Endpoint (AWS PrivateLink), whereas Gateway Endpoints are only available for Amazon S3 and DynamoDB.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway enables outbound internet access for private subnets, but it still requires traffic to traverse the internet, which contradicts the requirement to avoid internet traversal. Option B is wrong because the CloudWatch agent with a proxy does not eliminate internet dependency; a proxy typically routes traffic through an internet gateway or NAT, still using the public internet. Option C is wrong because attaching an Internet Gateway and assigning public IPs directly exposes instances to the internet, violating the private subnet requirement and the goal of avoiding internet traversal.

225
Matchingmedium

Match each AWS service to its primary use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Object storage

NoSQL database

Serverless compute

RESTful API creation

Message queuing

Why these pairings

Correct matches: Lambda is serverless compute, DynamoDB is NoSQL database, S3 is object storage, Elastic Beanstalk is PaaS. Common confusions include swapping Lambda and DynamoDB definitions.

← PreviousPage 3 of 6 · 388 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Dev AWS Services questions.